cch1 / http.async.client

Async Http Client - Clojure
http://cch1.github.com/http.async.client
267 stars 40 forks source link

CVE-2019-20445 through com.ning:async-http-client > io.netty:netty #94

Closed dubonzi closed 1 year ago

dubonzi commented 1 year ago

I see that com.ning:async-http-client is updated on master but the last release (1.3.1) is still using the vulnerable version. Is it possible to to release a new version with the updated dependency?

cch1 commented 1 year ago

I'll try to get to this issue shortly. Feel free to issue a PR with such a change if you find the motivation to tackle it first.

dubonzi commented 1 year ago

All needed is a new tag and release.

cch1 commented 1 year ago

Deployed version 1.4.0