Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2976 #4176

Open
heeh opened this issue Dec 6, 2023 · 1 comment
Open

CVE-2976 #4176

heeh opened this issue Dec 6, 2023 · 1 comment

Comments

@heeh
Copy link

heeh commented Dec 6, 2023

Thank you for releasing dagger 2.49.
Any plan for addressing CVE-2976?
image

@Chang-Eric
Copy link
Member

It looks like these vulnerabilities come from our Guava dependency (https://mvnrepository.com/artifact/com.google.guava/guava). Unfortunately due to some complexity in our implementation, our Guava version is actually tied to the version that Bazel uses when we build. Looking at their code, it seems they are not on a version high enough yet to not include those vulnerabilities https://github.com/bazelbuild/bazel/blob/1533cd123fa465480bbbcd4bdd2b438ebc5fb9eb/MODULE.bazel#L94. So I think this will take some time to resolve.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants