Join Slack
Powered by
New CVE mentioning Kotlin Multiplatform! CVE-2022...
# multiplatform
s
shaktiman_droid
02/25/2022, 7:32 PM
New CVE mentioning Kotlin Multiplatform! CVE-2022-24329 In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24329
b
Big Chungus
02/25/2022, 8:35 PM
Is this referring to npm locks or gradle locks as kmp often can use both
s
shaktiman_droid
03/01/2022, 7:05 PM
Not clear on that. Also their issue tracker link for this issue is not public so can't see more details
b
Big Chungus
03/01/2022, 7:06 PM
I'll assume it's referring to yarn.lock that only became persistent in 1.6.10
Big Chungus
03/01/2022, 7:06 PM
The timeline just seems right
s
shaktiman_droid
03/01/2022, 7:06 PM
yeah that makes sense and thus they did couple of public posts about it and then made it default setting as well in 1.6.0 or 1.6.10
👍 1
29
Views
Open in Slack
Previous
Next