Would not the right approach be, to report the CVE affected dependencies as gradle issues? So that the dependencies are bumped and included in a new gradle release?
Could you share the CVE numbers?
Would not the right approach be, to report the CVE affected dependencies as gradle issues? So that the dependencies are bumped and included in a new gradle release?
Could you share the CVE numbers?