Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade mapdb and dependency manage kerby #5035

Closed
hmottestad opened this issue Jun 18, 2024 · 0 comments · Fixed by #5036
Closed

Upgrade mapdb and dependency manage kerby #5035

hmottestad opened this issue Jun 18, 2024 · 0 comments · Fixed by #5036
Assignees
Labels
dependencies Pull requests that update a dependency file
Milestone

Comments

@hmottestad
Copy link
Contributor

Currently mapdb 3.0.9 has the following dependency vulnerability: https://devhub.checkmarx.com/cve-details/CVE-2022-24329/

We should upgrade to 3.0.10 or 3.1.0. Since 3.1.0 is already harvested and cleared by ClearlyDefined then we should try that version first.

There is also a licensing issue with the transitive dependency kerby which is used by solr. We should try to bump this to the next version without licensing issues.

@hmottestad hmottestad added the dependencies Pull requests that update a dependency file label Jun 18, 2024
@hmottestad hmottestad added this to the 5.0.0 milestone Jun 18, 2024
@hmottestad hmottestad self-assigned this Jun 18, 2024
hmottestad added a commit that referenced this issue Jun 18, 2024
…since this one has good enough license info for ClearlyDefined
hmottestad added a commit that referenced this issue Jun 18, 2024
…since this one has good enough license info for ClearlyDefined (#5036)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
1 participant