Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] Upgrade caffeine to 2.9.1 #10865

Merged
merged 1 commit into from
Jun 18, 2021

Conversation

lhotari
Copy link
Member

@lhotari lhotari commented Jun 9, 2021

Motivation

caffeine version 2.6.2 gets flagged as vulnerable in Sonatype IQ because of issue ben-manes/caffeine#301 .

Modifications

Upgrade caffeine version to 2.9.1 . This is the newest version for Java 8. (Caffeine releases 3.x are Java 11+)

@lhotari lhotari self-assigned this Jun 9, 2021
@lhotari lhotari added this to the 2.9.0 milestone Jun 9, 2021
@lhotari lhotari force-pushed the lh-upgrade-caffeine branch from 8c53203 to 822a82a Compare June 9, 2021 08:20
Copy link
Contributor

@eolivelli eolivelli left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@eolivelli eolivelli merged commit acf4149 into apache:master Jun 18, 2021
yangl pushed a commit to yangl/pulsar that referenced this pull request Jun 23, 2021
codelipenghui pushed a commit that referenced this pull request Jun 25, 2021
@codelipenghui codelipenghui added the cherry-picked/branch-2.8 Archived: 2.8 is end of life label Jun 25, 2021
bharanic-dev pushed a commit to bharanic-dev/pulsar that referenced this pull request Mar 18, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants