I think boot, lein and clojure tools are bringing in vulnerable maven resolver related packages, which I think have been fixed up stream.
I think the latest clojure tools has already been upgraded (though not released?) that does upgrade the offending packages, but I think lein and boot might still be a problem.
As per:
I think boot, lein and clojure tools are bringing in vulnerable maven resolver related packages, which I think have been fixed up stream.
I think the latest clojure tools has already been upgraded (though not released?) that does upgrade the offending packages, but I think lein and boot might still be a problem.