eclipse / lemminx

XML Language Server
Eclipse Public License 2.0
261 stars 90 forks source link

CVE of transitive dependencies #1650

Open kal-el11 opened 2 months ago

kal-el11 commented 2 months ago

Please update lemminx with updated versions of transitive dependencies to avoid jsoup CVE Reference : https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36033

angelozerr commented 2 months ago

Is there any chance to have a PR to fix that?

deathaxe commented 2 weeks ago

This would be https://github.com/eclipse/lemminx/pull/1618 then.

Note, there's already a 0.18.1