You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Dependency management is honored by most but not all (sub)dependencies, e.g. solr-solrj:jar:8.11.2 still uses 4.1.97
But it looks like this version of solr is only used at compile time for rdf4j-spring, and the included dependencies are OK (so probably another issue to pin down the solr-solrj version to 8.9.0 for all modules)
Current Behavior
I've noticed, when releasing the docker workbench image, there are a few vulnerabilities in netty (which may or may not affect RDF4J workbenc00h)
Expected Behavior
Upgrading to the latest (patch) release of netty should fix the reported CVEs for netty dependencies
Steps To Reproduce
No response
Version
5.0.0
Are you interested in contributing a solution yourself?
Yes
Anything else?
Might not be that straightforward, since netty is being used by (sub)dependencies, some excludes/includes in POMs can be expected
The text was updated successfully, but these errors were encountered: