Closed fdiotalevi closed 7 years ago
It's likely a minor issue, but I realised that pom-explorer relies on a quite old version of JGit that uses a vulnerable version of HttpClient. See
The PR just replaces the vulnerable version with the latest version on the 4.0.x branch
Thanks that's great ! I am merging your PR and maybe follow the other recommandations from the meterian web site. Thanks again 👍
Sorry I forgot to add your commit before closing the PR
It's likely a minor issue, but I realised that pom-explorer relies on a quite old version of JGit that uses a vulnerable version of HttpClient. See
The PR just replaces the vulnerable version with the latest version on the 4.0.x branch