Skip to content

Tomlj 1.1.1 - #51610

Open
gregallen wants to merge 2 commits into
spring-projects:mainfrom
gregallen:tom4j-1.1.1
Open

Tomlj 1.1.1#51610
gregallen wants to merge 2 commits into
spring-projects:mainfrom
gregallen:tom4j-1.1.1

Conversation

@gregallen

Copy link
Copy Markdown

Since tomlj 1.0.0 has dependency on vulnerable version of antlr4-runtime

Signed-off-by: Greg Allen <420943+gregallen@users.noreply.github.com>
Signed-off-by: Greg Allen <420943+gregallen@users.noreply.github.com>
@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged label Sep 7, 2026
@wilkinsona

Copy link
Copy Markdown
Member

Thanks for the PR. AFAIK, the recent Antlr4 vulnerabilities can only be exploited during grammar parsing/code generation and none of the affected classes are part of antlr4-runtime. Please clarify which vulnerabilities you believe this upgrade will fix.

@wilkinsona wilkinsona added the status: waiting-for-feedback We need additional information before we can continue label Sep 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status: waiting-for-feedback We need additional information before we can continue status: waiting-for-triage An issue we've not yet triaged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants