Skip to content

Vulnerabilities in pmd-bin-6.50.0 version #4157

Answered by adangel
DivyaSrivas asked this question in Q&A
Discussion options

You must be logged in to vote

protobuf-java is updated to 3.16.3 for the next version (PMD 6.51.0) -> f9ccab3

For jcommander, there is no version that is still compatible with Java 7 (Note: PMD 6 is still working with Java 7). Hence we didn't update it. The latest version seems to be 1.82 (https://repo1.maven.org/maven2/com/beust/jcommander/) and requires Java 8 (https://github.com/cbeust/jcommander/blob/aa70b568948d310899cda74e235733a8c23136ef/build.gradle.kts#L44).

The only vulnerability that I know of for jCommander is cbeust/jcommander#465 or https://security.snyk.io/vuln/SNYK-JAVA-COMBEUST-174815 . It's about the build script of jcommander - but we don't build jCommand from source, we use the already built jar, t…

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@DivyaSrivas
Comment options

Answer selected by DivyaSrivas
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants