Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dependency: bumped Google Guava version from 30.1-jre to 32.1.2-jre - CVE-2020-8908 CVE-2023-2976 #3868

Merged
merged 1 commit into from
Sep 18, 2023

Conversation

Coduz
Copy link
Contributor

@Coduz Coduz commented Sep 15, 2023

This PR bumps the version of Google Guava from 30.1-jre to 32.1.2-jre solving following CVEs:

Related Issue
None

Description of the solution adopted
Updated the version of the dependency

Screenshots
None

Any side note on the changes made
None

@Coduz Coduz added the Dependencies PR that updates dependencies. Be on the edge! label Sep 15, 2023
@codecov
Copy link

codecov bot commented Sep 15, 2023

Codecov Report

Merging #3868 (7090aa2) into develop (6ef61f8) will not change coverage.
The diff coverage is n/a.

❗ Current head 7090aa2 differs from pull request most recent head b8da435. Consider uploading reports for the commit b8da435 to get more accurate results

Impacted file tree graph

@@            Coverage Diff             @@
##             develop    #3868   +/-   ##
==========================================
  Coverage      20.59%   20.59%           
  Complexity         6        6           
==========================================
  Files           1936     1936           
  Lines          41532    41532           
  Branches        3945     3945           
==========================================
  Hits            8552     8552           
  Misses         32583    32583           
  Partials         397      397           

@Coduz Coduz merged commit 75fb64a into eclipse:develop Sep 18, 2023
@Coduz Coduz deleted the chng-bumpGuavaTo32.1.2-jre branch September 18, 2023 09:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Dependencies PR that updates dependencies. Be on the edge!
Projects
Development

Successfully merging this pull request may close these issues.

1 participant