Skip to content

Conversation

@emilie-robichaud
Copy link
Contributor

@emilie-robichaud emilie-robichaud commented Jan 16, 2025

issue: kotlin-maven-plugin relies on a vulnerable version of commons-io

This change mitigates this issue by forcing a safe version of commons-io in the dependency management section of the pom, which will take precedent over the existing, vulnerable version kotlin-maven-plugin was using. Intellij's vulnerable dependency tool now shows there are zero vulnerable dependencies for this project.

@emilie-robichaud emilie-robichaud force-pushed the master branch 2 times, most recently from 21ecb58 to 646f8a3 Compare January 29, 2025 19:48
@prathasirisha prathasirisha merged commit bad21ab into BNYMellon:master Jan 29, 2025
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants