Skip to content

xmlsec 2.2.3 vulnerabilities #422

@sedovalx

Description

@sedovalx

First, thank you for your work!

I noted that the latest released version of java-saml:2.9.0 depends on xmlsec:2.2.3 that has a known vulnerability. Also, the dependency is already updated to 3.0.2 (also has a major vulnerability) in the master branch. I'm wondering if you see it possible to release 2.9.1 with xmlsec:2.2.6 or release a new version of java-saml with xmlsec:3.0.3?

Metadata

Metadata

Assignees

No one assigned

    Labels

    PendingdependenciesPull requests that update a dependency file

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions