Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FLINK-36767] Bump cyclonedx-maven-plugin from 2.7.9 to 2.9.0 #917

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

r-sidd
Copy link
Contributor

@r-sidd r-sidd commented Nov 21, 2024

What is the purpose of the change

Bump commons-io from 2.11.0 to 2.17.0

Brief change log

Bump cyclonedx-maven-plugin from 2.7.9 to 2.9.0 to remediate the findings in the dependant packages.

Vulnerabilities from dependencies:
CVE-2024-38374

Package details:
https://mvnrepository.com/artifact/org.cyclonedx/cyclonedx-maven-plugin/2.9.0

Verifying this change

This change is a trivial rework / code cleanup without any test coverage.

Does this pull request potentially affect one of the following parts:

  • Dependencies (does it add or upgrade a dependency): yes
  • The public API, i.e., is any changes to the CustomResourceDescriptors: no
  • Core observer or reconciler logic that is regularly executed: no

Documentation

  • Does this pull request introduce a new feature? no
  • If yes, how is the feature documented? not applicable

@r-sidd r-sidd force-pushed the FLINK-36767-bump-cyclonedx-maven-plugin branch from db9a854 to e362d85 Compare November 21, 2024 10:54
@r-sidd r-sidd changed the title [FLINK-36469] Bump commons-io from 2.11.0 to 2.17.0 [FLINK-36767] Bump cyclonedx-maven-plugin from 2.7.9 to 2.9.0 Nov 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant