jbonofre commented on issue #2719:
URL: https://github.com/apache/karaf/issues/2719#issuecomment-4731374905

   @janpaul1988 my PR is fixing the actual security issue but it doesn't change 
the dependency, simply because it's not possible (due to Pax Web/Java 
requirement on the 4.4.x branch). So, even if the scanners might complain about 
the dependencies, there's no vulnerability in Karaf with the PR.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to