Skip to content

Commit 223db39

Browse files
K2GO-358 fix(deps): raise transitive kotlin-stdlib to 2.1.0 (Snyk)
Constrain kotlin-stdlib to 2.1.0 in :app and :termux-core to clear Snyk CVE-2020-29582. The stdlib is transitive via AndroidX; neither module has Kotlin source. Version-only and forward-compatible, so no behavior change.
1 parent 291949e commit 223db39

2 files changed

Lines changed: 11 additions & 0 deletions

File tree

‎controller/app/build.gradle‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -246,6 +246,9 @@ dependencies {
246246
implementation('com.squareup.okio:okio:1.17.6') {
247247
because 'Snyk CVE fix; transitive (was 1.17.5).'
248248
}
249+
implementation('org.jetbrains.kotlin:kotlin-stdlib:2.1.0') {
250+
because 'Snyk CVE-2020-29582 (removes deprecated kotlin.io temp-file helpers); transitive via AndroidX (was 1.9.24). No Kotlin source in this module.'
251+
}
249252
}
250253

251254
// ADFA-4533: GlitchTip (Sentry-compatible) crash reporting SDK.

‎controller/termux-core/build.gradle‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -114,6 +114,14 @@ if (System.getProperty("os.arch") == "aarch64"
114114
}
115115

116116
dependencies {
117+
// Security (Snyk): raise the transitive Kotlin stdlib. This module has no Kotlin
118+
// source; the stdlib arrives through AndroidX. Version-only, no behavior change.
119+
constraints {
120+
implementation('org.jetbrains.kotlin:kotlin-stdlib:2.1.0') {
121+
because 'Snyk CVE-2020-29582 (removes deprecated kotlin.io temp-file helpers); transitive via AndroidX (was 1.8.22).'
122+
}
123+
}
124+
117125
implementation 'androidx.appcompat:appcompat:1.7.1'
118126
implementation 'com.google.android.material:material:1.13.0'
119127

0 commit comments

Comments
 (0)