Skip to content

Conversation

@r-sidd
Copy link
Contributor

@r-sidd r-sidd commented Nov 21, 2024

What is the purpose of the change

Bump commons-io from 2.11.0 to 2.17.0

Brief change log

Bump cyclonedx-maven-plugin from 2.7.9 to 2.9.0 to remediate the findings in the dependant packages.

Vulnerabilities from dependencies:
CVE-2024-38374

Package details:
https://mvnrepository.com/artifact/org.cyclonedx/cyclonedx-maven-plugin/2.9.0

Verifying this change

This change is a trivial rework / code cleanup without any test coverage.

Does this pull request potentially affect one of the following parts:

  • Dependencies (does it add or upgrade a dependency): yes
  • The public API, i.e., is any changes to the CustomResourceDescriptors: no
  • Core observer or reconciler logic that is regularly executed: no

Documentation

  • Does this pull request introduce a new feature? no
  • If yes, how is the feature documented? not applicable

@r-sidd r-sidd force-pushed the FLINK-36767-bump-cyclonedx-maven-plugin branch from db9a854 to e362d85 Compare November 21, 2024 10:54
@r-sidd r-sidd changed the title [FLINK-36469] Bump commons-io from 2.11.0 to 2.17.0 [FLINK-36767] Bump cyclonedx-maven-plugin from 2.7.9 to 2.9.0 Nov 21, 2024
@gyfora gyfora merged commit 29c0403 into apache:main Apr 28, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants