aragozin / jvm-tools

Small set of tools for JVM troublshooting, monitoring and profiling.
Apache License 2.0
3.32k stars 518 forks source link

Vulnerable Dependency: jcommander 1.30 #71

Open sirkojac opened 3 years ago

sirkojac commented 3 years ago

https://github.com/aragozin/jvm-tools/blob/378285cc3b8a72a5547b428d8715b6665f91f95c/sjk-cli/pom.xml#L38 jcommander 1.30 is from 2012 and has a number of vulnerabilities. Should update to either jcommander 1.78 or 1.80