de4a-eu / de4a

DE4A WP5 Connector
Apache License 2.0
2 stars 5 forks source link

Toop Connector used as a compiled code dependeny #9

Closed daffyDukk closed 3 years ago

daffyDukk commented 3 years ago

https://github.com/de4a-wp5/de4a/blob/d47997f6deda975bc61f036432c1494e96ae3276/pom.xml#L67

The toop connector is used as compiled code dependency which is a security issue. On top of this it has previously created build problems as well as library transitivity problems which will probably happen again.

aosunacab commented 3 years ago

It would be solved by importing and setting photon and phase4 poms versions. POM