bhauman / rebel-readline

Terminal readline library for Clojure dialects
Eclipse Public License 1.0
680 stars 37 forks source link

Upgrade to latest stable clojurescript release to address protobuf vulnerability #210

Open kjothen opened 3 years ago

kjothen commented 3 years ago

Please refer to this vulnerability, "Upgrade com.google.protobuf:protobuf-java to version 3.4.0 or higher."

1.9.946

[org.clojure/clojurescript "1.9.946"]
   [com.google.javascript/closure-compiler-unshaded "v20170910"]
     ...
     [com.google.protobuf/protobuf-java "3.0.2"]

1.10.758

   [com.google.javascript/closure-compiler-unshaded "v20200315"]
      ...
      [com.google.protobuf/protobuf-java "3.11.1"]