Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update libthrift to version 0.12.0 #185

Open
goneall opened this issue Apr 7, 2019 · 5 comments
Open

Update libthrift to version 0.12.0 #185

goneall opened this issue Apr 7, 2019 · 5 comments

Comments

@goneall
Copy link
Member

goneall commented Apr 7, 2019

The current version used by Jena ARQ is 0.10.0 which has a medium severity CVE-2018-11798.

Although likely does not pose a threat to the current usage of libthrift within the SPDX tools, it should be upgraded to remove the vulnerability.

@goneall
Copy link
Member Author

goneall commented Apr 7, 2019

The POM file already has version 0.12.0 specified before Jena dependency. For some reason, 0.10.0 is still being included in the executables. Perhaps someone more familiar with POM files could take a look and see what the issue is and provide a PR to fix.

@imskr
Copy link

imskr commented Jun 7, 2020

@goneall Can I work on this?

@goneall
Copy link
Member Author

goneall commented Jun 7, 2020

@imskr Yes - thanks

@Gautime
Copy link
Contributor

Gautime commented Jun 16, 2020

@imskr Are you still working on it?

@imskr
Copy link

imskr commented Jun 16, 2020

Yeah

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants