Skip to content

Conversation

@johnduffell
Copy link

Just noticed that the readme is pointing at a version of logback with a high severity vulnerability, so I've just bumped the version to a safer one.

@SethTisue
Copy link
Collaborator

Just to check — you've verified that the newer version actually works in this context...?

@johnduffell
Copy link
Author

johnduffell commented Apr 22, 2024

Yes we are using it with no issues e.g. https://github.com/guardian/members-data-api/blob/a5bb9b3576536f362c144690712ac8922a943e47/project/Dependencies.scala#L30

although having said that intellij is letting me know that 1.5.6 is out by now!

@johnduffell
Copy link
Author

I've added another change to make the compile use that version too, as it makes no sense for me to leave it inconsistent.

@SethTisue
Copy link
Collaborator

@johnduffell so this now incorporates #432 ?

I can't approve this one or 432, the other maintainers need to make a choice here.

@jxnu-liguobin
Copy link
Collaborator

Thank you, this is redundant and will be resolved once #432 is merged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants