From 624f7c322deb26d38eb5bfac58a98d3796b4c187 Mon Sep 17 00:00:00 2001 From: Alexander01998 Date: Wed, 17 Apr 2024 17:17:02 +0200 Subject: [PATCH] Update com.diffplug.spotless to fix vulnerable sub-dependencies Specifically: CVE-2023-3635, caused by com.squareup.okio:okio version 3.2.0 and com.squareup.okio:okio-jvm version 3.2.0. This vulnerability doesn't affect end users of Wurst. Only developers were potentially affected. Then again, the attack vector for this CVE isn't super relevant when compiling Wurst. So, do update your forks, but don't worry too much. --- build.gradle | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/build.gradle b/build.gradle index 609b5554..41e912b0 100644 --- a/build.gradle +++ b/build.gradle @@ -7,7 +7,7 @@ buildscript { plugins { id 'fabric-loom' version '1.6-SNAPSHOT' id 'maven-publish' - id 'com.diffplug.spotless' version '6.23.3' + id 'com.diffplug.spotless' version '6.25.0' } def ENV = System.getenv()