The latest released version of tus-java-server contains org.apache.commons.io:commons-io:2.6 as a dependency, which is vulnerable to CVE-2021-29425. I noticed commons-io was updated in #41, but this change was never released to Maven Central. Is it easy to get another release of tus-java-server with the latest changes? Thanks!
The latest released version of
tus-java-server
containsorg.apache.commons.io:commons-io:2.6
as a dependency, which is vulnerable to CVE-2021-29425. I noticedcommons-io
was updated in #41, but this change was never released to Maven Central. Is it easy to get another release oftus-java-server
with the latest changes? Thanks!