Skip to content

SourceClear: fixes for vulnerable libraries#1

Open
Guiiii-m wants to merge 1 commit into
masterfrom
sourceclear-fix-20190924-150418.252
Open

SourceClear: fixes for vulnerable libraries#1
Guiiii-m wants to merge 1 commit into
masterfrom
sourceclear-fix-20190924-150418.252

Conversation

@Guiiii-m
Copy link
Copy Markdown
Owner

This pull request was generated by SourceClear to upgrade the following vulnerable libraries:

Type Library From To Breaking
MAVEN org.springframework:spring-web 3.1.1.RELEASE 4.3.20.RELEASE Yes
MAVEN org.neo4j:neo4j-jmx 1.3 3.0.0-M05 No
MAVEN com.h2database:h2 1.3.176 1.4.198 No
MAVEN org.apache.struts:struts2-core 2.5.12 2.5.17 No
MAVEN net.bull.javamelody:javamelody-core 1.59.0 1.74.0 No
MAVEN com.orientechnologies:orientdb-server 2.1.9 2.1.11 No
MAVEN org.keycloak:keycloak-saml-core 1.8.1.Final 2.5.5.Final No
MAVEN org.apache.sling:org.apache.sling.engine 2.0.4-incubator 2.4.6 No
MAVEN org.apache.kafka:kafka_2.11 0.9.0.1 0.10.2.2 No
MAVEN org.mindrot:jbcrypt 0.3m 0.4 Yes

Note that we only upgrade libraries which have versions without any known vulnerabilities. For more information, please see the corresponding SourceClear report.

The Breaking column states the likelihood that updating to the recommended library version will cause breaking changes in your code. Please verify that the changes here won't cause issues with your project before merging.

To learn more about this feature, please visit our Help Center for documentation.

Note: this pull request was generated because you or someone else with access to this repository granted SourceClear access to submit pull requests.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants