Skip to content

Conversation

nmisch
Copy link

@nmisch nmisch commented May 3, 2025

This project references junit only in pom.xml. This removes the need to keep the pom.xml junit version number fresh.

https://mvnrepository.com/artifact/com.github.jnr/jnr-x86asm/1.0.2 shows
"Vulnerabilities from dependencies: CVE-2020-15250" due to old junit. Commit
945f73b already increased the junit version sufficiently, so the next jnr-x86asm
release would clear that alert. However, jnr-x86asm doesn't actually use junit.

This project references junit only in pom.xml.  This removes the need to keep
the pom.xml junit version number fresh.
@nmisch
Copy link
Author

nmisch commented Aug 3, 2025

Can someone look at this? If not, could we get a release from today's git, so
the latest release stops having an unpatched CVE on its record?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant