LinuxForHealth / hl7v2-fhir-converter

Converts HL7 v2 Messages to FHIR Resources
Apache License 2.0
86 stars 34 forks source link

Multiple security patches in dependencies #498

Closed snesm closed 1 year ago

snesm commented 1 year ago

Updates to mitigate vulnerabilities in dependencies or sub-dependencies:

Critical org.thymeleaf:thymeleaf Sandbox Bypass High net.minidev:json-smart Denial of Service (DoS) Medium org.yaml:snakeyaml Arbitrary Code Execution Medium com.squareup.okio:okio-jvm Denial of Service (DoS) Low com.google.guava:guava Information Disclosure Low com.google.guava:guava Creation of Temporary File in Directory with Insecure Permissions Low org.jetbrains.kotlin:kotlin-stdlib Information Exposure

snesm commented 1 year ago

@LisaWellman @pbhallam @klwhaley @evbaron: any chance of getting these security fixes merged and released?

klwhaley commented 1 year ago

@LisaWellman @pbhallam @klwhaley @evbaron: any chance of getting these security fixes merged and released?

Reviewing now! Will work with @LisaWellman to get a release out as well.