Upplication / Amazon-S3-FileSystem-NIO2

An S3 File System Provider for Java 7
MIT License
122 stars 67 forks source link

[SECURITY] Upgrade guava to 25.1-jre #109

Closed kemitix closed 1 year ago

kemitix commented 6 years ago

Guava 18.0 is susceptible to CWE-502: Deserialization of Untrusted Data

kemitix commented 6 years ago

I could be looking at it wrong, but it doesn't appear that PRs are configured to run integration tests properly on Travis.

takaczapka commented 6 years ago

Is anyone looking at those problems? My PR is failing for the same reason.

kemitix commented 6 years ago

@takaczapka No new commits in four months, and no response to a security-related PR. I'm not optimistic about this being actively maintained.