Closed thraco closed 3 months ago
@thraco thanks for brining this into attention, we will release a patch asap
thanks @azlam-abdulsalam!
We are facing some issues while rebuilding apexlink, will keep everyone posted when the patch is ready
Fantastic, thank you @azlam-abdulsalam !
Describe the bug
49 did not completely resolve the issue raised in #46 by @JonnyPower. scala-library:2.13.3 is still included in the published packages for 38.4.1 and 39.0.3. #47 was closed without merging, but did include the upgrade of this package to 2.13.13.
To Reproduce Steps to reproduce the behavior:
Expected behavior sfp-lite no longer includes scala-library:2.13.3, which has the critical vulnerability CVE-2022-36944