j-easy / easy-rules

The simple, stupid rules engine for Java
https://github.com/j-easy/easy-rules/wiki
MIT License
4.83k stars 1.04k forks source link

SonaType Security Issue Due to jackson-core #409

Open LarryBullock opened 1 year ago

LarryBullock commented 1 year ago

IQ Server is reporting a transitive dependency issue for j-easy.easy-rules due to a transitive dependency on jackson-core (sonatype-2022-6438: CWE-400: Uncontrolled Resource Consumption ('Resource Exhaustion') - Sonatype OSS Index).](https://ossindex.sonatype.org/vulnerability/sonatype-2022-6438)). It is looking like Jackson-Core will be updating soon(ish). Will you be updating and redeploying j-easy-rules in order to accommodate this update so we can continue to use j-easy-rules?