Hi ANTLR maintainers,
Our security scanning tool (Snyk) has reported CVE's against org.antlr:antlr4:4.13.2.
The dependency is introduced transitively through Micronaut Data:
promotion-authoring
└── io.micronaut.data:micronaut-data-processor
└── org.antlr:antlr4:4.13.2
Screenshot:
We also verified that the latest available version of io.micronaut.data:micronaut-data-processor (5.0.6) still depends on org.antlr:antlr4:4.13.2, so upgrading Micronaut does not currently resolve the vulnerability.
Hi ANTLR maintainers,
Our security scanning tool (Snyk) has reported CVE's against org.antlr:antlr4:4.13.2.
The dependency is introduced transitively through Micronaut Data:
Screenshot:
We also verified that the latest available version of io.micronaut.data:micronaut-data-processor (5.0.6) still depends on org.antlr:antlr4:4.13.2, so upgrading Micronaut does not currently resolve the vulnerability.