Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

A new 4.x version of okhttp is needed with the okio upgrade #7946

Closed
KritiRajput opened this issue Jul 21, 2023 · 5 comments
Closed

A new 4.x version of okhttp is needed with the okio upgrade #7946

KritiRajput opened this issue Jul 21, 2023 · 5 comments
Labels
enhancement Feature not a bug

Comments

@KritiRajput
Copy link

KritiRajput commented Jul 21, 2023

According to https://square.github.io/okhttp/security/security/, only 4.x and 5.x are actively supported.

When looking at the different okhttp changelog (https://square.github.io/okhttp/changelogs/changelog/), it does not seem that there is any version using the okio 3.4.0 9 (even in the 5.x alpha releases).

A PR has been merged in the okhttp master branch to do the upgrade (#7932) but it is included in any of the actual releases yet.

This new version is required to resolve security vulnerability CVE-2023-3635.

If a backport to 3.x or even 2.x is possible then that would be really great.

@KritiRajput KritiRajput added the enhancement Feature not a bug label Jul 21, 2023
@JakeWharton
Copy link
Collaborator

Dupe of #7944

@KritiRajput
Copy link
Author

@JakeWharton Could you please re-open this issue, until a new version is released. I observed that #7944 is closed. But this issue is w.r.t new version. So I would request you to please keep it open until a new version is released. Thank you !

@lggomezsf
Copy link

@JakeWharton I agree with @KritiRajput, is there a target date for the new release?

@JakeWharton
Copy link
Collaborator

I do not work on the project in a capacity to provide such updates. I'm just triaging the duplicates to help out.

@yschimke
Copy link
Collaborator

There is also a 4.x bump here #7947, But waiting on a release.

If it's really blocking you, you can bump Okio yourself. You will not be vulnerable after that. Are the tools flagging against your project even when you depend on the latest version of Okio?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement Feature not a bug
Projects
None yet
Development

No branches or pull requests

4 participants