-
Notifications
You must be signed in to change notification settings - Fork 404
Open
Labels
PendingdependenciesPull requests that update a dependency filePull requests that update a dependency file
Description
First, thank you for your work!
I noted that the latest released version of java-saml:2.9.0 depends on xmlsec:2.2.3 that has a known vulnerability. Also, the dependency is already updated to 3.0.2 (also has a major vulnerability) in the master branch. I'm wondering if you see it possible to release 2.9.1 with xmlsec:2.2.6 or release a new version of java-saml with xmlsec:3.0.3?
usr42 and jbakoc1
Metadata
Metadata
Assignees
Labels
PendingdependenciesPull requests that update a dependency filePull requests that update a dependency file