-
Notifications
You must be signed in to change notification settings - Fork 5.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix spring jar security vulnerabilities #24112
base: master
Are you sure you want to change the base?
Conversation
Suggest adding a release note entry that links to the CVE. Something in the format of the following example:
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please add references to CVEs that are fixed.
Done |
Done |
Please squash these commits and make sure the commit message follows our guidelines in contributing. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@NivinCS Please also read https://github.com/prestodb/presto/wiki/Release-Notes-Guidelines and update the release note accordingly. The phrase should start with Fix...
Also the PR message should also use imperative present tense.
e8cabf9
to
7f1ad6c
Compare
7f1ad6c
to
6d44d7d
Compare
Done |
Done |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Release note
Fix for ...
==>
Fix ...
cc @steveburnett
Hi @steveburnett / @yingsu00 , Could you please confirm the same, as we get the general template for release note as below == RELEASE NOTES == General Changes
Hive Connector Changes
|
Description
Fixing OSS CVEs for critical, high, and medium transitive vulnerabilities in the benchto-driver jar originating from Spring JARs
Motivation and Context
CVE-2016-1000027
CVE-2018-1272
CVE-2022-22970
CVE-2024-22243
CVE-2024-22259
CVE-2021-22096
CVE-2024-8184
CVE-2024-6763
CVE-2021-22060
CVE-2024-22262
CVE-2021-22096
CVE-2023-20883
WS-2021-0170
CVE-2018-1199
CVE-2022-22965
CVE-2024-6763
CVE-2015-5211
CVE-2015-3192
CVE-2022-27772
CVE-2020-5421
CVE-2024-38809
CVE-2022-22970
Impact
Test Plan
Contributor checklist
Release Notes
Please follow release notes guidelines and fill in the release notes below.