rackerlabs / repose

The powerful, programmable, API Middleware Platform
http://www.openrepose.org/
Other
338 stars 103 forks source link

REP-7776 Upgrading okhttp to resolve CVE-2018-20200 #2057

Closed dmnjohns closed 5 years ago

dmnjohns commented 5 years ago

The dependency check plugin is flagging an issue with our transitive dependency on okhttp (via jaeger-core).

Unfortunately, upgrading jaeger-core does not resolve this issue for us at this time. So instead we upgrade the library directly, preferring that to suppressing the issue.

wdschei commented 5 years ago

Retest this please.