You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Our dependency scanner is upset about the CVE-2023-3635 vulnerability in com.squareup.okio:okio v3.2.0 that is contained within okhttp3 v4.11.0. See dependency tree below:
Using v4.12.0 will bring us to okio v3.6.0 that is no longer vulnerable. Better would be to remove dependency on these square http libraries entirely, but I think the version bump is an easy change.
The text was updated successfully, but these errors were encountered:
Another helpful thing would be suggesting use of dependabot on statsig-io's repositories, which would help these items to be remedied sooner (without me asking).
rhanton
added a commit
to rhanton/java-server-sdk
that referenced
this issue
Mar 11, 2025
Our dependency scanner is upset about the CVE-2023-3635 vulnerability in com.squareup.okio:okio v3.2.0 that is contained within okhttp3 v4.11.0. See dependency tree below:
Using v4.12.0 will bring us to okio v3.6.0 that is no longer vulnerable. Better would be to remove dependency on these square http libraries entirely, but I think the version bump is an easy change.
The text was updated successfully, but these errors were encountered: