Thanks for checking this. I am seeing that https://issues.apache.org/jira/browse/MSHARED-1292 is closed. But I am not able to find maven-archiver, 3.6.1 in mvnrepository <https://mvnrepository.com/artifact/org.apache.maven/maven-archiver> yet.
On Wed, Aug 9, 2023 at 4:51 PM Slawomir Jaranowski <s.jaranow...@gmail.com> wrote: > Hi > > Next version of maven-archiver is ready for release. > > I can release new version in next week. > > > https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12317922&version=12353169 > > > wt., 8 sie 2023, 14:12 użytkownik Debraj Manna <subharaj.ma...@gmail.com> > napisał: > > > Hi > > > > maven-archiver is getting flagged for CVE-2023-37460 > > <https://nvd.nist.gov/vuln/detail/CVE-2023-37460> in our vulnerability > > scans. But I am seeing the latest version of maven-archiver (3.6.0) is > > still using plexus-archiver 4.4.0. > > > > Is there any plan to upgrade plexus-archiver to 4.8.0 in maven-archiver? > > > > Thanks > > >