Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bump guava version from 30.1.1-jre to 32.1.1-jre #33

Merged
merged 1 commit into from
Jul 8, 2023

Conversation

datYori
Copy link
Contributor

@datYori datYori commented Jul 5, 2023

Sine guava 30.1.1-jre is problematic CVE-2023-2976 we bump it to 32.1.1-jre

@inkytonik inkytonik self-requested a review July 8, 2023 04:24
@inkytonik
Copy link
Owner

Thanks for the bump. All looks good.

@inkytonik inkytonik merged commit 23ba1a8 into inkytonik:master Jul 8, 2023
1 check passed
@datYori
Copy link
Contributor Author

datYori commented Jul 10, 2023

Thanks for the quick response though.
Can we have a new tag and release to maven central from this commit then ? Like v2.5.1 for example ?

@datYori
Copy link
Contributor Author

datYori commented Jul 10, 2023

or maybe feel free to merge this first #34 and then bundle both deps update in the same v2.5.1 release

@inkytonik
Copy link
Owner

Thanks. I've applied #34. I'll get a new release out fairly soon.

datYori added a commit to raw-labs/snapi that referenced this pull request Jul 20, 2023
The current version is causing a transitive dep vuln issue (check JIRA
for more details)

Thanks to @inkytonik responsivness on
inkytonik/kiama#33 and
inkytonik/kiama#34 we can now bump to `2.5.1`
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants