spdx / spdx-java-jackson-store

JSON storage implementation for the SPDX tools
Apache License 2.0
4 stars 8 forks source link

Update JSON and Jackson library versions #53

Closed goneall closed 1 year ago

goneall commented 1 year ago

this PR is in draft mode until there is a new release of the JSON library with https://github.com/stleary/JSON-java/pull/720 released. This will resolve a stack overflow DOS vulnerability (CVE-2022-45688).

Signed-off-by: Gary O'Neall gary@sourceauditor.com