Update Mend: high confidence minor and patch dependency updates #3
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.10.4
->2.10.9.2
2.5
->2.18.0
2.5.1
->2.5.2
9.37.3
->9.48
1.7.25
->1.7.36
32.0.1-jre
->32.1.3-jre
4.27.0
->4.29.3
1.14.0
->1.16.0
9.3
->9.7.1
2.2.2
->2.3.1
2.5.0
->2.5.2
1.13.1
->1.18.3
3.18.0
->3.26.3
4.1.4
->4.2.30
1.2
->1.9.0
2.8.2
->2.10.0
2.23.2
->2.35.2
3.4.38
->3.7.3
2.0
->2.4
0.9.12
->0.10.2
3.6.2
->3.9.9
1.11.0
->1.32.1
1.8.1
->1.11.4
6.0.3
->6.0.11
3.11
->3.17.0
2.9.6
->2.52.0
2.8.0
->2.18.0
2.2.3-1
->2.3.9
5.10.0
->5.16.0
1.6.5
->1.7.0
1.4.5
->1.4.7
1.16.2
->1.19.0
12.27.1
->12.29.0
5.8.1
->5.11.4
1.5.0
->1.5.3
4.2.0
->4.2.1
9.7
->9.7.1
9.7
->9.7.1
1.1.4
->1.1.10
0.9.10
->0.9.14
4.4.12
->4.4.16
2.15.1
->2.18.0
1.26.1
->1.27.1
2.4.0
->2.4.1
3.42.0
->3.49.0
2.2
->2.18.0
2.17.2
->2.18.2
1.11
->1.18.0
1.31.0
->1.47.0
1.10.12
->1.10.15
5.8.1
->5.11.4
5.8.1
->5.11.4
2.15.0
->2.18.2
2.15.0
->2.18.2
2.15.0
->2.18.2
9.6
->9.7.1
9.6
->9.7.1
Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
netplex/json-smart-v2 (net.minidev:json-smart)
v2.5.2
Compare Source
About CVE-2024-57699
Thanks for @ccudennec-otto Some remarks on the CVE, more discussions in #236
com.nimbusds:oauth2-oidc-sdk
MODE_RFC4627
JSONParser
manually / with custom options, make sure you set optionLIMIT_JSON_DEPTH
JSONParser
setup on their side, i.e. you rather need their fixed version and not version 2.5.2 of json-smartWhat's Changed
New Contributors
Full Changelog: netplex/json-smart-v2@2.5.1...2.5.2
connect2id/nimbus-jose-jwt (com.nimbusds:nimbus-jose-jwt)
[
v9.48
](https://bitbucket.org/connect2id/nimbus-jose-jwt/branchesConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
disabled