Skip to content
This repository has been archived by the owner on Oct 23, 2024. It is now read-only.

Bump various dependencies, resolves CVE-2023-25158, CVE-2023-24998 #3501

Merged
merged 2 commits into from
Feb 23, 2023

Conversation

mprins
Copy link
Member

@mprins mprins commented Feb 23, 2023

  • geotools.version: 25.6 ⇨ 25.7 (resolves CVE-2023-25158)
  • postgresql.version: 42.5.1 ⇨ 42.5.4
  • mssql.version: 11.2.1.jre8 ⇨ 11.2.3.jre8
  • oracle.version: 21.7.0.0 ⇨ 21.9.0.0
  • apache.httpcomponents.version: 4.5.13 ⇨ 4.5.14
  • slf4j.version: 2.0.5 ⇨ 2.0.5
  • jackson2.version: 2.14.0 ⇨ 2.0.5
  • commons-fileupload: 1.4 ⇨ 1.6 (CVE-2023-24998)

Also update the Maven plugins

@codecov
Copy link

codecov bot commented Feb 23, 2023

Codecov Report

Merging #3501 (05c5879) into v5.8.x (e724b79) will not change coverage.
The diff coverage is n/a.

Additional details and impacted files

Impacted file tree graph

@@           Coverage Diff            @@
##             v5.8.x   #3501   +/-   ##
========================================
  Coverage        15%     15%           
  Complexity      533     533           
========================================
  Files           218     218           
  Lines         20485   20485           
  Branches       3027    3027           
========================================
  Hits           3083    3083           
  Misses        17026   17026           
  Partials        376     376           

Continue to review full report at Codecov.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 5929dfe...05c5879. Read the comment docs.

@mprins mprins changed the title Bump various dependencies, resolves CVE-2023-25158 Bump various dependencies, resolves CVE-2023-25158, CVE-2023-24998 Feb 23, 2023
@mprins mprins self-assigned this Feb 23, 2023
@mprins mprins merged commit 4d87c23 into v5.8.x Feb 23, 2023
@mprins mprins deleted the dependency-updates branch February 23, 2023 15:13
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant