Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade maven-assembly-plugin to 3.7.1 - CVE-2023-37460 (replaces #674) #675

Conversation

camille-hdl
Copy link
Contributor

see #673, in which I explain that I'm not used to the Java ecosystem and I'm interested in advice on how to solve this correctly if this PR is not the right way.

Replaces #674 which targeted release/5.0 to target develop instead.

This bumps plexus-archiver to 4.9.2, which fixes CVE-2023-37460 (starting from 4.8)

see:

Copy link
Contributor

@DiegoPino DiegoPino left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Was previously approved against 5.0.

@glenrobson
Copy link
Contributor

Great thank you! We can look at this in the meeting tomorrow and hopefully merge.

@camille-hdl
Copy link
Contributor Author

Thanks!
I see the meeting is on EU time so I'll see if I can make it, although it would be purely out of curiosity as I don't think i'll be able to offer any valuable input :)

@jcoyne jcoyne merged commit a6ec5c3 into cantaloupe-project:develop Jul 31, 2024
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants