starjava icon indicating copy to clipboard operation
starjava copied to clipboard

Vulnerabilities from libraries used by stil

Open pahjbo opened this issue 1 year ago • 4 comments

looking at https://mvnrepository.com/artifact/uk.ac.starlink/stil/4.3 it is clear that there are some fairly serious security vulnerabilities in the json and yaml library dependencies - it would be good to update these (the json one is 10yrs old!)

pahjbo avatar Aug 16 '24 13:08 pahjbo

Thanks @pahjbo you are right. This is really just a case of updating the POM, I've been using snakeyaml v2.2 in development for a while now so the snakeyaml version in the POM is an oversight, and there are no source changes required for an update of JSON-java to 20240303. I've made changes so that the next STIL release should have these versions in the POM so that the CVEs go away. I can't easily test this without actually making a release, so I will leave this issue open until the next release, when I'll try to remember to check that this has actually happened.

mbtaylor avatar Aug 27 '24 17:08 mbtaylor

I guessed that was probably the case - so it is fine for local use to override what the POM is saying before the next official release.

pahjbo avatar Aug 29 '24 10:08 pahjbo

Correct. BTW from what I can tell the chances of users suffering security issues based on these vulnerabilities in practice seems rather remote.

mbtaylor avatar Aug 29 '24 10:08 mbtaylor

Correct. BTW from what I can tell the chances of users suffering security issues based on these vulnerabilities in practice seems rather remote.

probably but that security red light is rather binary - I only noticed it because the IDE that I use flashed up a warning at me!

pahjbo avatar Aug 29 '24 12:08 pahjbo

I believe that the JSON-java-related warnings should have gone away for the most recent central-repo release of STIL, v4.3-1. If you get the chance, can you confirm and close the issue, thanks.

mbtaylor avatar Nov 06 '24 12:11 mbtaylor

And a happy new year to you Mr Theduck.

mbtaylor avatar Jan 11 '25 13:01 mbtaylor

forgot to close earlier, but certainly no security warnings against 4.3.3

pahjbo avatar Sep 01 '25 09:09 pahjbo