What is the process for vulnerability remediation? #2323
|
The latest release of cucumber-spring has a transitive vulnerability with one of its dependencies: messages-ndjson > jackson My team is waiting on a fix for this, just wondering about the process for fixing vulnerabilities and if there is a timeline that I can bring back to my team. |
Replies: 2 comments 4 replies
So instead of waiting have you taken actions to actually providing a PR or similar? |
|
@JKaulback It depends. You can always email security@cucumber.io. Though for problems that already have a CVE creating an issue against https://github.com/cucumber/messages-ndjson would the most efficient approach. |
@JKaulback It depends. You can always email security@cucumber.io. Though for problems that already have a CVE creating an issue against https://github.com/cucumber/messages-ndjson would the most efficient approach.