web3j
web3j copied to clipboard
Outdated okhttp dependency has several security vulnerabilities
The okhttp and logging-interceptor dependencies (along with their own transitive dependencies) have a bunch of vulnerabilities:
https://github.com/square/okhttp/issues/6738
https://github.com/square/okio/pull/1280
https://blog.jetbrains.com/blog/2022/02/08/jetbrains-security-bulletin-q4-2021/
I'm not sure if these vulnerabilities are an actual issue for web3j but they have been addressed already so upgrading isn't a bad idea