Skip to content

Add a Kotlin dependency to work around CVE-2022-24329#7660

Merged
yschimke merged 3 commits into
square:okhttp_4.10.xfrom
yschimke:okio_4x
Jan 22, 2023
Merged

Add a Kotlin dependency to work around CVE-2022-24329#7660
yschimke merged 3 commits into
square:okhttp_4.10.xfrom
yschimke:okio_4x

Conversation

@yschimke

@yschimke yschimke commented Jan 18, 2023

Copy link
Copy Markdown
Collaborator

fixes #7654

@yschimke

Copy link
Copy Markdown
Collaborator Author

That didn't work because okio is kotlin 1.8. Not sure I want to bring that in for OkHttp 4.x at this time.

So took a different approach.

Comment thread okhttp/build.gradle
@swankjesse

Copy link
Copy Markdown
Collaborator

Found it. #7654

@swankjesse swankjesse changed the title [4.x] Bump okio to 3.3.0 Add a Kotlin dependency to work around CVE-2022-24329 Jan 22, 2023
@yschimke yschimke merged commit cbcf4f3 into square:okhttp_4.10.x Jan 22, 2023
@yschimke yschimke deleted the okio_4x branch February 18, 2023 14:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants