Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update testng and guava for security patches #10

Closed
smugleafdev opened this issue Dec 5, 2023 · 2 comments
Closed

Update testng and guava for security patches #10

smugleafdev opened this issue Dec 5, 2023 · 2 comments

Comments

@smugleafdev
Copy link

Dependabot has two open PRs. They are tied to active CVEs. It would be helpful if they were accepted and a new release pushed.

@AutomatedOwl
Copy link
Owner

done

@sphanley
Copy link

Thanks for the action on this, @AutomatedOwl! I'm sad to report though that unfortunately Dependabot has led things astray here – because of the odd ordering of the releases, it apparently superseded its PR for 7.7.0 with 7.5.1, rather than 7.7.1 or 7.8.0. CVE-2022-4065 is fixed in versions > 7.7.0, so is there any chance you'd be able to update further to 7.7.1 or 7.8.0?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants