REXML和可寻址的安全性漏洞
我目前有一个正在生产的 Flutter 项目,不久前我看到 dependentabot 中弹出了两个安全漏洞,如下所示:
我不太熟悉本机代码,所以不确定如何修复这些依赖关系。
除了等待包所有者更新他们的库之外,还有什么方法可以强制使用 Gemfile 的最低版本吗?
I have a Flutter project currently in production, and I have seen a while ago two security vulnerabilities pop up in dependabot, see below:
I am not really acquainted with native code, so am unsure on how to fix these dependencies.
Apart from waiting for packages owners to update their libraries, is there a way for me to force a minimum version for the Gemfile?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
data:image/s3,"s3://crabby-images/d5906/d59060df4059a6cc364216c4d63ceec29ef7fe66" alt="扫码二维码加入Web技术交流群"
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
找到了这个问题,它与本机代码无关,也与扑动代码无关。所有这些都与fastlane及其副依赖性(我使用firebase_app_distribution和upload_to_to_browserstack_app_live packages)绑定
,以解决任何遇到这个问题的人,请执行以下步骤:
fast fast fast fast fast fast fast lane fast_fastlane )
Bundle Update
)Fastlane Update_plugins
。这应该将软件包升级到最新版本,希望已经解决了安全漏洞。
Found the issue, it was not related to native code, nor to Flutter code. All was tied to Fastlane and its subdependecies (I use firebase_app_distribution and upload_to_browserstack_app_live packages)
In order to fix, for anyone stumbling upon this question, do these steps:
fast lane update_fastlane
)bundle update
)fastlane update_plugins
.This should upgrade the packages to the latest versions, hopefully that have fixed the security vulnerabilities.