Skip to content

Conversation

bbimber
Copy link
Contributor

@bbimber bbimber commented Aug 21, 2025

This PR is designed to address CVE-2024-7254: https://nvd.nist.gov/vuln/detail/CVE-2024-7254.

The commons-lang and -io updates are not strictly needed, but they were flagged too, and the GATK repo is using those versions.

@bbimber
Copy link
Contributor Author

bbimber commented Sep 9, 2025

Hello @yfarjoun and @lbergelson: I'm not sure where to reach out on this, but you two made recent commits to picard. The practical risk here is probably low, but it's also an easy update to address the CVE. Is there a chance someone would be willing to look at this PR?

@lbergelson
Copy link
Contributor

lbergelson commented Sep 10, 2025 via email

@bbimber
Copy link
Contributor Author

bbimber commented Sep 10, 2025

@lbergelson: i had no idea - thanks for you help over the years and best of luck to you!

@bbimber
Copy link
Contributor Author

bbimber commented Sep 22, 2025

Hi @yfarjoun - by chance do you still have access to this repo? if not, do you know who is managing this repo now?

@lbergelson
Copy link
Contributor

@bbimber Thank you. It was a pleasure working with you. All the best!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants