Not bumping commons-io from 2.6 to 2.7
commons-io 2.7 would require java8. The risk for https://github.com/advisories/GHSA-gwrp-pvrq-jmwv (CVE-2021-29425) is tolerable here. FilenameUtils.normalize is only used in tests or while generating the ruledoc in module pmd-doc.
This commit is contained in:
parent
f62f97f832
commit
4250130e94
Loading…
x
Reference in New Issue
Block a user