You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi, it seems that the spring-cloud-starter-contract-stub-runner has a transitive dependency on plexus-utils:3.0.18. This version of plexus-utils seems to be vulnerable: https://avd.aquasec.com/nvd/2022/cve-2022-4244/
From what I can tell, this dependency comes from the following:
Hi, it seems that the
spring-cloud-starter-contract-stub-runner
has a transitive dependency onplexus-utils:3.0.18
. This version of plexus-utils seems to be vulnerable: https://avd.aquasec.com/nvd/2022/cve-2022-4244/From what I can tell, this dependency comes from the following:
2.6.0
, which is from 2015 ⚠spring-cloud-contract/spring-cloud-contract-starters/spring-cloud-starter-contract-stub-runner/pom.xml
Lines 80 to 83 in f320eb6
sisu plexus
?sisu-inject-plexus
entirely?Thanks in advance! 😄
The text was updated successfully, but these errors were encountered: