Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade maven-assembly-plugin to fix CVE-2023-37460 in plexus-archiver #673

Closed
camille-hdl opened this issue Jul 30, 2024 · 1 comment
Closed

Comments

@camille-hdl
Copy link
Contributor

Hello,

I'm trying to fix this vulnerability in Cantaloupe 5 (and future versions obviously).
I'm not a Java developer so I'm a bit lost in the tooling but I tried to change the version number here : camille-hdl@a2cdd0f

I saw previous work done on fixing vulnerabilities in the dependencies in #634 , but apparently there was no acceptable release of maven-assembly-plugin available at the time. I believe there is one now (3.7.1 or 3.7.0).

I started by branching off of develop and ran the CI workflow on my own repo, which seemed to work at least for the windows builds. I then branched off of release/5.0 and will submit a PR shortly.

As I said, I'm not used to the Java ecosystem (or contributing to other projects on GitHub in general), so I apologize if I did this the wrong way and I'm willing to try again should anyone be willing to offer me guidance.

Thank you for your work on Cantaloupe

Camille

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants