bkiers / Liqp

An ANTLR based 'Liquid Template' parser and rendering engine.
MIT License
165 stars 94 forks source link

Upgrade jsoup to 1.15.3 #232

Closed stephen-murby closed 2 years ago

stephen-murby commented 2 years ago

Upgrade the jsoup dependency as it has a listed vulnerability.

https://www.cve.org/CVERecord?id=CVE-2022-36033

stephen-murby commented 2 years ago

Built the library locally to confirm there are no build failures.

stephen-murby commented 2 years ago

I have just seen that 'dependabot' has already submitted the same changes in a PR, closing this one.

msangel commented 2 years ago

making release with that. thanks!