snyk / gradle-plugin

Snyk Gradle Plugin - Scanning and monitoring your dependencies for security vulnerabilities from Gradle
Other
20 stars 19 forks source link

Version 0.4 still contains vulnerability to org.json #27

Closed mishabhi closed 1 year ago

mishabhi commented 1 year ago

It is visible from the commit https://github.com/snyk/gradle-plugin/commit/a80054aa0ec29fe9a77c8462905c8d198005aea5 that the org.json dependency is upgraded but it appears the plugin on gradle repository is still 0.4.

Because of above synchronization mismatch, this plugin itself is producing a high level of vulnerability.

image

Please may I request to publish a new plugin version with the latest changes?

josephearl commented 1 year ago

+1, can we get a release of the plugin please?

bmvermeer commented 1 year ago

0.5 just released