Investigate exclusion of woodstox dependency

Description

Santuario/xmlsec depends on woodstox, a StAX library, which apparently has some current CVEs open. It may be impossible to yank due to the way xmlsec initializes, but we should at least look into it.

Environment

None

Activity

Scott CantorJanuary 3, 2023 at 3:47 PM

Applied to both branches based on apparently having no impact on IdP.

Done

Details

Assignee

Reporter

Fix versions

Created October 31, 2022 at 3:22 PM
Updated January 18, 2023 at 1:05 PM
Resolved January 3, 2023 at 3:48 PM