Skip to content

Update dependencies. #664

@matsreeves-nasstar

Description

@matsreeves-nasstar

Affected version

Latest

Bug description

The dependencies need to be bumped to newer versions to resolve CVE warnings.

In particular, org.apache.rat:apache-rat-plugin needs to have its version explicitly specified (latest is 0.17) rather than relying on the parent version (currently at 0.16.1), as the latter has a CVE in transitive dependency org.apache.commons:commons-text at version 1.3.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions