From 3b004810035460aab21c9b7ab7cc9734045e85bf Mon Sep 17 00:00:00 2001 From: Julian Psotta Date: Wed, 7 Jun 2023 13:46:31 +0200 Subject: [PATCH 1/2] fix(cve): Upgrade kafka_2.13 from 3.4.0 to 3.4.1 This fixes the GHSA-jgvc-jfgh-rjvv from the jose4j dependency from the kafka_2.13 package. --- openrouteservice/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/openrouteservice/pom.xml b/openrouteservice/pom.xml index 5c10eb3605..1d851d6635 100644 --- a/openrouteservice/pom.xml +++ b/openrouteservice/pom.xml @@ -50,7 +50,7 @@ 29.0 2.0.7 2.20.0 - 3.4.0 + 3.4.1 2.15.0 GIScience_openrouteservice giscience From 0a3b7dcfa1ff8a8cfab0b9ecc2dfcd46bd91d217 Mon Sep 17 00:00:00 2001 From: Julian Psotta Date: Wed, 7 Jun 2023 13:46:31 +0200 Subject: [PATCH 2/2] fix(cve): Upgrade kafka_2.13 from 3.4.0 to 3.4.1 This fixes the GHSA-jgvc-jfgh-rjvv from the jose4j dependency from the kafka_2.13 package. --- CHANGELOG.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 3547aa9fe5..2af8bb704e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -61,6 +61,8 @@ RELEASING: - Upgrade geotools from 28.2 to 29.0 [#1422](https://github.com/GIScience/openrouteservice/pull/1422) - upgrade graphhopper version to v4.6 [#1427](https://github.com/GIScience/openrouteservice/pull/1427) - Map matching of traffic data ([#1430](https://github.com/GIScience/openrouteservice/pull/1430)) +- Upgrade kafka_2.13 from 3.4.0 to 3.4.1 ([#1463](https://github.com/GIScience/openrouteservice/issues/1463)) + ### Removed - AccelerationWeighting ([#1454](https://github.com/GIScience/openrouteservice/pull/1454))