android-analyzer icon indicating copy to clipboard operation
android-analyzer copied to clipboard

Old Detekt version includes snakeYAML with high CVE score

Open stephannielsen opened this issue 4 years ago • 1 comments

The use version of detekt (1.0.1) includes an old version of snakeYAML (1.24) which has a reported CVE of score 7.5 (high): https://nvd.nist.gov/vuln/detail/CVE-2017-18640

We are checking our app against known CVEs and this is failing the build.

An update of the plugin with updated dependencies (and also fixing #25) would be appreciated.

stephannielsen avatar Aug 31 '20 08:08 stephannielsen

We're currently experiencing the same problem in our team. Hope we get an update soon :)

AresProductions avatar Nov 03 '20 09:11 AresProductions