We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
A critical CVE has been found in https://github.com/KnpLabs/snappy : GHSA-gq6w-q6wh-jggc
This CVE has been fixed in snappy 1.4.2, but the minimum requirement in latest KnpSnappyBundle is snappy 1.2.
Change the minimum version to 1.4.2 doesn't seem to be a problem, and can avoid to download versions with vunlerabilities
The text was updated successfully, but these errors were encountered:
Hello, Thanks for reporting, we will have a look at it soon.
Sorry, something went wrong.
Fixed in https://github.com/KnpLabs/KnpSnappyBundle/releases/tag/v1.9.1
alexpozzi
No branches or pull requests
A critical CVE has been found in https://github.com/KnpLabs/snappy : GHSA-gq6w-q6wh-jggc
This CVE has been fixed in snappy 1.4.2, but the minimum requirement in latest KnpSnappyBundle is snappy 1.2.
Change the minimum version to 1.4.2 doesn't seem to be a problem, and can avoid to download versions with vunlerabilities
The text was updated successfully, but these errors were encountered: