bzip2 should be upgraded
Closed this issue · 1 comments
avl commented
See CVE-2023-22895
avl commented
Ok, turns out we only refer to bzip2 by version "0.4", which already covers the fixed version.
Thus, this CVE is not really relevant for savefile.
I got a dependabot-warning from github, but that was because we had old unused lock-files checked into the repo. I've removed them.
Closing this now.