Skip to content

Bump org.clojure/clojure from 1.11.0 to 1.12.0#9

Open
nthmost-orkes wants to merge 1 commit intomainfrom
fix/bump-clojure-version
Open

Bump org.clojure/clojure from 1.11.0 to 1.12.0#9
nthmost-orkes wants to merge 1 commit intomainfrom
fix/bump-clojure-version

Conversation

@nthmost-orkes
Copy link

Summary

  • Bumps org.clojure/clojure from 1.11.0 to 1.12.0 (latest stable) to address GHSA-vr64-r9qj-h27f
  • This vulnerability allows specially crafted serializable objects from an untrusted source to cause an infinite loop

Fixes #8

Test plan

  • Verify Clojure SDK compiles and tests pass with Clojure 1.12.0
  • Confirm no breaking API changes from 1.11.0 to 1.12.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[GHSA-vr64-r9qj-h27f] org.clojure:clojure@1.10.3: Deserialization infinite loop

1 participant