-
Notifications
You must be signed in to change notification settings - Fork 23
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
SDKS-2988 Resolve the CVE-2023-52428 issue by upgrading the nimbus-jose-jwt #396
Conversation
|
||
override fun apply(project: Project) { | ||
project.android().apply { | ||
compileSdk = 34; |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
What do you think about use a constant or property file to avoid the need to change the code directly in a new version?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
It seems not straightforward to use the variable in toml, may consider it in another story.
forgerock-auth-ui/src/main/java/org/forgerock/android/auth/ui/SingleLiveEvent.java
Outdated
Show resolved
Hide resolved
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good to me
…se-jwt. Other enhancement are included in this PR: 1. Centralize the version in toml file. 2. Refactor Core and Auth module build.gradle file to build.gradle.kts 3. Since the root detector is moved to core, move the jni folder from auth to core. 4. introduce buildSrc to share common configuration. 5. Remove lombok from forgerock-auth-ui and remove doc and build for forgerock-auth-ui
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM! 👍🏻
JIRA Ticket
SDKS-2988
Description
Resolve the CVE-2023-52428 issue by upgrading the nimbus-jose-jwt
Other enhancements are included in this PR: