libexpat 2.5.0 considered vulnerable
Open
- Dominant language
- C++
- Stars
- 262
- Forks
- 110
- PR merge metrics
- No merged PRs in 30d
Description
As far as I can tell this is not a security issue for `XMP-Toolkit-SDK`, but `libexpat` `2.5.0` is considered vulnerable.
`libexpat` seems like a source of many vulnerabilities and might need constant updating.
see also #73
Contributor guide
Research direction
Review how libexpat 2.5.0 is used in XMP-Toolkit-SDK and read the related issue #73 first. Confirm whether the reported vulnerability affects this project and identify the required update or rationale for keeping the current version. Done means the dependency concern has a documented resolution.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cpp
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100