Skip to content

Managed Dependencies #867

Discussion options

You must be logged in to vote

Yes, it was an accidental metadata leak which should be resolved in 396a940 and 7321a56. The security scanners were warning about test libraries and build plugin transitive dependencies, I suppose because exploits of CI/CD are becoming more common threats now. The dependency constraints leaked into the external metadata. I was hoping to do a final review of the changes and release this week.

Replies: 1 comment 4 replies

Comment options

You must be logged in to vote
4 replies
@ben-manes
Comment options

@ralmeida-espatial
Comment options

@ben-manes
Comment options

@ben-manes
Comment options

Answer selected by ben-manes
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants