spdx / LicenseListPublisher

Tool that generates license data found in the license-list-data repository from the license-list-XML source
Apache License 2.0
11 stars 18 forks source link

Update SPDX Library version to 1.0.10 #126

Closed goneall closed 2 years ago

goneall commented 2 years ago

Updates log4j to version 2.17.0 resolving possible vulnerabilities CVE-2021-44228 and CVE-2021-45046

Note that the current usage of the licenseListPublisher makes it unlikely this vulnerability would be exploited.

Signed-off-by: Gary O'Neall gary@sourceauditor.com