07-09-2018 11:43 AM
We are running with Activiti version 6.0.0, and are noticing that security scans reveal security vulnerabilities with the following two transitive dependencies:
In both cases I notice that there are later versions of these libraries available. In the case of jackson-databind, version 2.9.6 ; and in the case of commons-email, version 1.5.
Are there plans to upgrade these dependencies in future releases of activiti?
07-11-2018 08:23 AM
These libs have been upgraded in the latest code base of 6.x branch
07-11-2018 08:43 AM
Bassam,
Many thanks for this. Really appreciate the good news, and the prompt reply.
Regards
Steve Gioberti
Explore our Alfresco products with the links below. Use labels to filter content by product module.