ltearno / pom-explorer

A tool to aid managing lots of maven projects
MIT License
371 stars 65 forks source link

Updated JGit to a version that has a patched HttpClient #36

Closed fdiotalevi closed 7 years ago

fdiotalevi commented 7 years ago

It's likely a minor issue, but I realised that pom-explorer relies on a quite old version of JGit that uses a vulnerable version of HttpClient. See

The PR just replaces the vulnerable version with the latest version on the 4.0.x branch

ltearno commented 7 years ago

Thanks that's great ! I am merging your PR and maybe follow the other recommandations from the meterian web site. Thanks again 👍

ltearno commented 7 years ago

Sorry I forgot to add your commit before closing the PR