closure-compiler icon indicating copy to clipboard operation
closure-compiler copied to clipboard

Bump gson from 2.7 to 2.9.1

Open cmuchinsky opened this issue 2 years ago • 0 comments

This should resolve https://github.com/google/closure-compiler/issues/3957, which I believe was closed prematurely without a fix. This is needed because the closure-compiler jar is being flagged with CVE-2022-25647 as a result of the shaded version of gson 2.7 inside it.

cmuchinsky avatar Aug 10 '22 20:08 cmuchinsky