ndw / xmlcalabash1

XML Calabash, an XProc processor
http://xmlcalabash.com/
108 stars 41 forks source link

Check on vulnerabilities (bump versions) #320

Closed ndw closed 3 years ago

ndw commented 3 years ago

Nexus reports: junit/junit@4.12, org.apache.httpcomponents/httpclient@4.5.8, org.apache.logging.log4j/log4j-core@2.12.1, and xerces/xercesImpl@2.9.1 (I suspect the Xerces vulnerability is the billion laughs attack.)

ndw commented 3 years ago

Fixed in 1.3.2.