Skip to content

Conversation

@adamnfish-gu
Copy link
Contributor

This allows applications using this libary to safely update to Play 3.0.10, to resolve the lz4 vulnerabilities.

There are some other versions that might want bumping, but since the 3.0.10 Pay release has been driven by a security vulnerbaility it might make sense to make a minimal change here.

This allows applications using this libary to safely update to Play
3.1.10, to resolve the lz4 vulnerabilities.
@adamnfish-gu
Copy link
Contributor Author

Just to help get us started on a release, no worries if this isn't the right approach here @mkurz

@mkurz mkurz merged commit aac66c7 into webjars:main Dec 23, 2025
6 checks passed
@mkurz
Copy link
Collaborator

mkurz commented Dec 23, 2025

@adamnfish-gu I will try to cut a new release now

@adamnfish-gu adamnfish-gu deleted the update-for-play-3.0.10 branch December 23, 2025 15:37
@mkurz
Copy link
Collaborator

mkurz commented Dec 23, 2025

@adamnfish-gu 3.0.10 is out: https://repo1.maven.org/maven2/org/webjars/webjars-play_2.13/3.0.10/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants