Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security: upgrade com.google.guava:guava to 32.0.0-jre #6069

Merged
merged 2 commits into from
Nov 25, 2023

Conversation

imcmai
Copy link
Contributor

@imcmai imcmai commented Nov 21, 2023

What happened?

There are 1 security vulnerabilities found in com.google.guava:guava 30.1-jre

What did I do?

Upgrade com.google.guava:guava from 30.1-jre to 32.0.0-jre for vulnerability fix

What did you expect to happen?

Ideally, no insecure libs should be used.

@CLAassistant
Copy link

CLAassistant commented Nov 21, 2023

CLA assistant check
All committers have signed the CLA.

@funky-eyes funky-eyes added this to the 2.x Backlog milestone Nov 21, 2023
Copy link

codecov bot commented Nov 21, 2023

Codecov Report

Merging #6069 (ef24ed0) into 2.x (ded33d1) will increase coverage by 0.03%.
The diff coverage is n/a.

❗ Current head ef24ed0 differs from pull request most recent head d3505dc. Consider uploading reports for the commit d3505dc to get more accurate results

Additional details and impacted files

Impacted file tree graph

@@             Coverage Diff              @@
##                2.x    #6069      +/-   ##
============================================
+ Coverage     49.44%   49.48%   +0.03%     
- Complexity     4745     4751       +6     
============================================
  Files           908      908              
  Lines         31354    31354              
  Branches       3777     3777              
============================================
+ Hits          15504    15516      +12     
+ Misses        14309    14306       -3     
+ Partials       1541     1532       -9     

see 4 files with indirect coverage changes

Copy link
Contributor

@funky-eyes funky-eyes left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

请登记pr和作者信息至 https://github.com/seata/seata/tree/2.x/changes 中的2.x.md中
Please register the PR and author information in the 2.x.md file located at https://github.com/seata/seata/tree/2.x/changes

@imcmai imcmai mentioned this pull request Nov 22, 2023
1 task
@imcmai
Copy link
Contributor Author

imcmai commented Nov 22, 2023

请登记pr和作者信息至 https://github.com/seata/seata/tree/2.x/changes 中的2.x.md中 Please register the PR and author information in the 2.x.md file located at https://github.com/seata/seata/tree/2.x/changes

ok

Copy link
Contributor

@funky-eyes funky-eyes left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@funky-eyes funky-eyes changed the title fix(sec): upgrade com.google.guava:guava to 32.0.0-jre security: upgrade com.google.guava:guava to 32.0.0-jre Nov 25, 2023
@funky-eyes funky-eyes merged commit 09097aa into apache:2.x Nov 25, 2023
7 checks passed
@funky-eyes funky-eyes modified the milestones: 2.x Backlog, 2.1.0 Nov 25, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Development

Successfully merging this pull request may close these issues.

3 participants