Open leafnunes opened 5 years ago
The meta-buildpack package required for decorator packages is not being maintained, and pulls in a version of cf-cli which has an open CVE.
This should be deprecated (or supported) to avoid package producers shipping vulnerable applications.
We have created an issue in Pivotal Tracker to manage this. Unfortunately, the Pivotal Tracker project is private so you may be unable to view the contents of the story.
The labels on this github issue will be updated when the story is started.
The meta-buildpack package required for decorator packages is not being maintained, and pulls in a version of cf-cli which has an open CVE.
This should be deprecated (or supported) to avoid package producers shipping vulnerable applications.