Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

⬆️ Bump commons-configuration2 from 2.9.0 to 2.10.1 - CVE-2024-29131 #4037

Merged
merged 1 commit into from
May 16, 2024

Conversation

MDeLuise
Copy link
Contributor

This pull request addresses CVE-2024-29131 by updating the org.apache.commons:commons-configuration2 library to the 2.10.1 version.
The vulnerability posed a risk, and this update mitigates it effectively.

@codecov-commenter
Copy link

codecov-commenter commented May 16, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 16.67%. Comparing base (c215cc9) to head (3fd460d).
Report is 2 commits behind head on develop.

Additional details and impacted files

Impacted file tree graph

@@              Coverage Diff              @@
##             develop    #4037      +/-   ##
=============================================
- Coverage      16.71%   16.67%   -0.04%     
  Complexity        22       22              
=============================================
  Files           2009     2009              
  Lines          52223    52223              
  Branches        4437     4437              
=============================================
- Hits            8728     8708      -20     
- Misses         43092    43112      +20     
  Partials         403      403              

see 2 files with indirect coverage changes

@Coduz Coduz added the Dependencies PR that updates dependencies. Be on the edge! label May 16, 2024
@Coduz Coduz merged commit ba33d87 into eclipse:develop May 16, 2024
33 checks passed
@MDeLuise MDeLuise deleted the improve-bumpCommonsConfiguration2 branch May 16, 2024 15:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Dependencies PR that updates dependencies. Be on the edge!
Projects
Development

Successfully merging this pull request may close these issues.

3 participants