Skip to content

Commit 3b7987a

Browse files
Merge pull request #28 from contentstack/staging
DX | 05-01-2026 | Release
2 parents 132e783 + f1d2252 commit 3b7987a

4 files changed

Lines changed: 28 additions & 3 deletions

File tree

‎.idea/misc.xml‎

Lines changed: 0 additions & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎CHANGELOG.md‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,2 +1,13 @@
11
# CHANGELOG
22

3+
## v0.0.3
4+
5+
### Jan 05, 2026
6+
7+
- Snyk Fixes
8+
9+
## v0.0.2
10+
11+
### Oct 29, 2025
12+
13+
- Security Fixes

‎LICENSE‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
The MIT License (MIT)
2-
Copyright © 2012-2025 Contentstack. All Rights Reserved
2+
Copyright © 2012-2026 Contentstack. All Rights Reserved
33

44
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and
55
associated documentation files (the "Software"), to deal in the Software without restriction,

‎app/build.gradle‎

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ android {
1313
minSdkVersion 24
1414
targetSdkVersion 34
1515
versionCode 1
16-
versionName "0.0.2"
16+
versionName "0.0.3"
1717
}
1818
buildTypes {
1919
release {
@@ -39,6 +39,21 @@ dependencies {
3939
implementation 'androidx.constraintlayout:constraintlayout:2.1.4'
4040
implementation 'androidx.lifecycle:lifecycle-livedata:2.7.0'
4141
implementation 'androidx.lifecycle:lifecycle-viewmodel:2.7.0'
42+
43+
// Security fixes for transitive dependencies
44+
// Fix CVE-2022-25647 (Deserialization vulnerability in Gson)
45+
implementation 'com.google.code.gson:gson:2.10.1'
46+
// Fix CVE-2020-29582 (Information Exposure in kotlin-stdlib)
47+
implementation 'org.jetbrains.kotlin:kotlin-stdlib:2.1.0'
48+
}
49+
50+
// Force all kotlin-stdlib versions to 2.1.0 (fixes CVE-2020-29582 from transitive deps like Realm)
51+
configurations.all {
52+
resolutionStrategy {
53+
force 'org.jetbrains.kotlin:kotlin-stdlib:2.1.0'
54+
force 'org.jetbrains.kotlin:kotlin-stdlib-jdk7:2.1.0'
55+
force 'org.jetbrains.kotlin:kotlin-stdlib-jdk8:2.1.0'
56+
}
4257
}
4358

4459
mavenPublishing {

0 commit comments

Comments
 (0)