webcompere / model-assert

Assertions for data models
MIT License
28 stars 3 forks source link

Is the mode-assert still under development? #42

Closed hannah23280 closed 1 year ago

hannah23280 commented 1 year ago

Hi, Is this library still under development? Cos the last update is 2021, so not sure what is the future plan for this. In addition, one of its dependency Jackson-databind has 3 vulnerabilities, as indicate on https://mvnrepository.com/artifact/uk.org.webcompere/ModelAssert/1.0.0. Any plan to use the Jackson-databind library's latest version to avoid these vulnerabilities?

ashleyfrieze commented 1 year ago

Hey @hannah23280 - I'm happy to update dependencies. The library is not presently being extended, but I'm happy to resolve issues with it.

You can replace the jackson-databind dependencies with your own, and everything should still work.

I'll look at a 1.0.1 to resolve this in the near future.

ashleyfrieze commented 1 year ago

@hannah23280 - I've merged an update without the Jackson and Snake vulnerabilties. Hope this helps. Please raise issues with any bugs/feature requests you may have, or comment on any other of the issues in there.