From 9c32d26c0d13b90ca7120eda454aaee04a09b38b Mon Sep 17 00:00:00 2001 From: LamGC Date: Mon, 19 Sep 2022 14:32:40 +0800 Subject: [PATCH] =?UTF-8?q?fix(dependencies):=20=E6=9B=B4=E6=96=B0=20Commo?= =?UTF-8?q?ns-codec=20=E4=BE=9D=E8=B5=96=E9=A1=B9=E7=9A=84=E7=89=88?= =?UTF-8?q?=E6=9C=AC.?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 由于目前从 TelegramBots-Abilities 引入的 Commons-codec 存在 Base 32 和 64 的编解码漏洞, 考虑到需要防范潜在的安全问题, 因此决定更新 Commons-codec 的版本号. ---------------- 参考链接: https://devhub.checkmarx.com/cve-details/Cxeb68d52e-5509/ --- scalabot-extension/build.gradle.kts | 1 + 1 file changed, 1 insertion(+) diff --git a/scalabot-extension/build.gradle.kts b/scalabot-extension/build.gradle.kts index f64a016..ddb3e01 100644 --- a/scalabot-extension/build.gradle.kts +++ b/scalabot-extension/build.gradle.kts @@ -8,6 +8,7 @@ plugins { } dependencies { + implementation("commons-codec:commons-codec:1.15") api("org.telegram:telegrambots-abilities:6.1.0") api("org.slf4j:slf4j-api:2.0.0")