Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump snakeyaml and jackson-databind to latest versions #201

Merged
merged 2 commits into from May 16, 2024

Conversation

dgrad
Copy link
Contributor

@dgrad dgrad commented Dec 21, 2023

Previous versions had known vulenerabilities.

Vulnerabilities
NAME              INSTALLED  FIXED-IN  TYPE          VULNERABILITY        SEVERITY
jackson-databind  2.13.4     2.13.4.2  java-archive  GHSA-jjjh-jjxp-wpff  High
snakeyaml         1.28       1.31      java-archive  GHSA-hhhw-99gj-p3c3  Medium
snakeyaml         1.28       2.0       java-archive  GHSA-mjmj-j48q-9wg2  High
snakeyaml         1.28       1.32      java-archive  GHSA-w37g-rhq8-7m4j  Medium
snakeyaml         1.28       1.31      java-archive  GHSA-3mc7-4q67-w48m  High
snakeyaml         1.28       1.31      java-archive  GHSA-98wm-3w3q-mw94  Medium
snakeyaml         1.28       1.32      java-archive  GHSA-9w3m-gqgf-c4p9  Medium
snakeyaml         1.28       1.31      java-archive  GHSA-c4r9-r8fh-9vj2  Medium

All tests passing and tested with local sonarqube instance.

@zippy1978 zippy1978 changed the base branch from master to develop January 10, 2024 08:42
@zippy1978
Copy link
Contributor

Thank you @dgrad !
I changed the PR target branch to develop

@zippy1978 zippy1978 merged commit 426cc38 into insideapp-oss:develop May 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants