Closed brendanarnold closed 1 year ago
@brendanarnold FYI: A similar update has been merged into the edge
branch at #compdemocracy/polis. Will probably be doing some additional work soon to pull out some libraries that aren't being used anymore.
Thanks!
@brendanarnold FYI: A similar update has been merged into the edge branch at #compdemocracy/polis. Will probably be doing some additional work soon to pull out some libraries that aren't being used anymore.
Thanks @metasoarous good to know - there are a couple of vulnerabilities that are from semantic-csv
that would be good to squash - I've put an issue against that repo here https://github.com/metasoarous/semantic-csv/issues/75 it looks like a version bump on clojurescript should do it.
Addresses issue #49
docker scan polis-math:latest
now results in 2 low severity issues in the Alpine Docker base image and 1 low inpolis-math
metasaurus/oz
to a developer dependency (removes vulnerableprotobuf-java
,netty-codec
,jetty-http
inring
,soup
,snakeyaml
from production code)amazonica
and other AWS libraries (removes vulnerableguava
,nippy
,httpclient
)Updatealready at latest (uses vulnerablesemantic-csv
gson
andprotobuf-java
)Updatealready at latest (uses vulnerablekorma
c3p0
)commons/collection
to 3.2.2cli-excel
(uses vulnerablepoi
)ring
(uses vulnerablejetty-http
)clj-http
to 3.12.3 (uses vulnerablecommons-codec
)clojure/tools
MATH_ENV
variable in template - necessary for data exportmath