pekko pulls in the vulnerable `org.lz4:lz4-java:1.8.0` dependency. They have fixed this in the `1.4.0` milestone (https://github.com/apache/pekko/pull/2539) This ticket to track upgrading when possible.
pekko pulls in the vulnerable
org.lz4:lz4-java:1.8.0dependency.They have fixed this in the
1.4.0milestone (apache/pekko#2539)This ticket to track upgrading when possible.