You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi @yazgoo , ScalaPB is not affected by CVE-2024-7254 as it has its own code for parsing unknown fields. If you do have Java code that relies on that, you should directly depend on protobuf-java and use an affected version.
Regardless, I'll cut a release in the coming days to bump up dependencies - it's been a while.
Hello
I see that 1.0.0 alpha fixes a lot of CVEs (especially CVE-2024-7254).
I have two questions:
I asked this on the mailing list but did not get answers.
Thank you !
The text was updated successfully, but these errors were encountered: