Bump the maven group across 21 directories with 13 updates#17
Open
dependabot[bot] wants to merge 1 commit intomainfrom
Open
Bump the maven group across 21 directories with 13 updates#17dependabot[bot] wants to merge 1 commit intomainfrom
dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the maven group with 3 updates in the /SecVulns/VulnCore/Command directory: [org.springframework:spring-core](https://github.com/spring-projects/spring-framework), commons-io:commons-io and org.apache.commons:commons-lang3. Bumps the maven group with 1 update in the /SecVulns/VulnCore/Expression/ELAttack directory: org.apache.logging.log4j:log4j-core. Bumps the maven group with 3 updates in the /SecVulns/VulnCore/Expression/OGNLAttack directory: [org.springframework:spring-core](https://github.com/spring-projects/spring-framework), commons-io:commons-io and org.apache.commons:commons-lang3. Bumps the maven group with 1 update in the /SecVulns/VulnCore/FilesOperations directory: commons-io:commons-io. Bumps the maven group with 1 update in the /SecVulns/VulnCore/Inject/SQL directory: [com.microsoft.sqlserver:mssql-jdbc](https://github.com/Microsoft/mssql-jdbc). Bumps the maven group with 1 update in the /SecVulns/VulnCore/JDBCAttack directory: [org.springframework:spring-context](https://github.com/spring-projects/spring-framework). Bumps the maven group with 2 updates in the /SecVulns/VulnCore/JNDIAttack directory: org.apache.tomcat:tomcat-catalina and [com.thoughtworks.xstream:xstream](https://github.com/x-stream/xstream). Bumps the maven group with 1 update in the /SecVulns/VulnCore/MemShellAndRceEcho/JakartaTomcatDemo directory: org.apache.tomcat:tomcat-catalina. Bumps the maven group with 1 update in the /SecVulns/VulnCore/MemShellAndRceEcho/JavaxJettyDemo directory: commons-fileupload:commons-fileupload. Bumps the maven group with 2 updates in the /SecVulns/VulnCore/MemShellAndRceEcho/JavaxTomcatDemo directory: org.apache.tomcat:tomcat-catalina and commons-fileupload:commons-fileupload. Bumps the maven group with 1 update in the /SecVulns/VulnCore/MemShellAndRceEcho/LowTomcatDemo directory: commons-fileupload:commons-fileupload. Bumps the maven group with 1 update in the /SecVulns/VulnCore/MemShellAndRceEcho/OSEcho directory: org.apache.tomcat:tomcat-catalina. Bumps the maven group with 1 update in the /SecVulns/VulnCore/MemShellAndRceEcho/ResinDemo directory: commons-fileupload:commons-fileupload. Bumps the maven group with 1 update in the /SecVulns/VulnCore/SSRF directory: [com.squareup.okhttp3:okhttp](https://github.com/square/okhttp). Bumps the maven group with 2 updates in the /SecVulns/VulnCore/Serialization/ClassLoad directory: [org.springframework:spring-core](https://github.com/spring-projects/spring-framework) and [org.mozilla:rhino](https://github.com/mozilla/rhino). Bumps the maven group with 1 update in the /SecVulns/VulnCore/Serialization/ConstructorEXP directory: [org.springframework:spring-context](https://github.com/spring-projects/spring-framework). Bumps the maven group with 1 update in the /SecVulns/VulnCore/Serialization/FastjsonDemo directory: [com.alibaba:fastjson](https://github.com/alibaba/fastjson). Bumps the maven group with 1 update in the /SecVulns/VulnCore/Serialization/SnakeyamlDemo directory: [com.alibaba:fastjson](https://github.com/alibaba/fastjson). Bumps the maven group with 1 update in the /SecVulns/VulnCore/Serialization/XMLSerialization/XStreamAttack directory: [com.thoughtworks.xstream:xstream](https://github.com/x-stream/xstream). Bumps the maven group with 1 update in the /SecVulns/VulnCore/XXE directory: [org.jdom:jdom2](https://github.com:/hunterhacker/jdom). Bumps the maven group with 1 update in the /Utils directory: [com.thoughtworks.xstream:xstream](https://github.com/x-stream/xstream). Updates `org.springframework:spring-core` from 5.3.18 to 6.2.11 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v5.3.18...v6.2.11) Updates `commons-io:commons-io` from 2.2 to 2.14.0 Updates `org.apache.commons:commons-lang3` from 3.12.0 to 3.18.0 Updates `org.apache.logging.log4j:log4j-core` from 2.14.1 to 2.25.3 Updates `org.springframework:spring-core` from 5.3.18 to 6.2.11 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v5.3.18...v6.2.11) Updates `commons-io:commons-io` from 2.2 to 2.14.0 Updates `org.apache.commons:commons-lang3` from 3.12.0 to 3.18.0 Updates `commons-io:commons-io` from 2.2 to 2.14.0 Updates `com.microsoft.sqlserver:mssql-jdbc` from 9.2.1.jre8 to 11.2.0.jre8 - [Release notes](https://github.com/Microsoft/mssql-jdbc/releases) - [Changelog](https://github.com/microsoft/mssql-jdbc/blob/main/CHANGELOG.md) - [Commits](https://github.com/Microsoft/mssql-jdbc/commits) Updates `org.springframework:spring-context` from 5.3.28 to 6.1.20 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v5.3.28...v6.1.20) Updates `org.apache.tomcat:tomcat-catalina` from 8.5.78 to 9.0.112 Updates `com.thoughtworks.xstream:xstream` from 1.4.17 to 1.4.21 - [Release notes](https://github.com/x-stream/xstream/releases) - [Commits](https://github.com/x-stream/xstream/commits) Updates `org.apache.tomcat:tomcat-catalina` from 11.0.0-M1 to 11.0.14 Updates `commons-fileupload:commons-fileupload` from 1.5 to 1.6.0 Updates `org.apache.tomcat:tomcat-catalina` from 8.0.53 to 9.0.112 Updates `commons-fileupload:commons-fileupload` from 1.5 to 1.6.0 Updates `commons-fileupload:commons-fileupload` from 1.5 to 1.6.0 Updates `org.apache.tomcat:tomcat-catalina` from 8.5.82 to 9.0.112 Updates `commons-fileupload:commons-fileupload` from 1.5 to 1.6.0 Updates `com.squareup.okhttp3:okhttp` from 3.14.9 to 4.9.2 - [Changelog](https://github.com/square/okhttp/blob/master/CHANGELOG.md) - [Commits](square/okhttp@parent-3.14.9...parent-4.9.2) Updates `org.springframework:spring-core` from 5.3.18 to 6.2.11 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v5.3.18...v6.2.11) Updates `org.mozilla:rhino` from 1.7.14 to 1.7.14.1 - [Release notes](https://github.com/mozilla/rhino/releases) - [Changelog](https://github.com/mozilla/rhino/blob/master/RELEASE-NOTES.md) - [Commits](https://github.com/mozilla/rhino/commits) Updates `org.springframework:spring-context` from 5.3.28 to 6.1.20 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v5.3.28...v6.1.20) Updates `com.alibaba:fastjson` from 1.2.47 to 1.2.83 - [Release notes](https://github.com/alibaba/fastjson/releases) - [Commits](alibaba/fastjson@1.2.47...1.2.83) Updates `com.alibaba:fastjson` from 1.2.47 to 1.2.83 - [Release notes](https://github.com/alibaba/fastjson/releases) - [Commits](alibaba/fastjson@1.2.47...1.2.83) Updates `com.thoughtworks.xstream:xstream` from 1.4.12 to 1.4.21 - [Release notes](https://github.com/x-stream/xstream/releases) - [Commits](https://github.com/x-stream/xstream/commits) Updates `org.jdom:jdom2` from 2.0.6 to 2.0.6.1 - [Commits](hunterhacker/jdom@JDOM-2.0.6...JDOM-2.0.6.1) Updates `com.thoughtworks.xstream:xstream` from 1.4.12 to 1.4.21 - [Release notes](https://github.com/x-stream/xstream/releases) - [Commits](https://github.com/x-stream/xstream/commits) --- updated-dependencies: - dependency-name: org.springframework:spring-core dependency-version: 6.2.11 dependency-type: direct:production dependency-group: maven - dependency-name: commons-io:commons-io dependency-version: 2.14.0 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.commons:commons-lang3 dependency-version: 3.18.0 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.logging.log4j:log4j-core dependency-version: 2.25.3 dependency-type: direct:production dependency-group: maven - dependency-name: org.springframework:spring-core dependency-version: 6.2.11 dependency-type: direct:production dependency-group: maven - dependency-name: commons-io:commons-io dependency-version: 2.14.0 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.commons:commons-lang3 dependency-version: 3.18.0 dependency-type: direct:production dependency-group: maven - dependency-name: commons-io:commons-io dependency-version: 2.14.0 dependency-type: direct:production dependency-group: maven - dependency-name: com.microsoft.sqlserver:mssql-jdbc dependency-version: 11.2.0.jre8 dependency-type: direct:production dependency-group: maven - dependency-name: org.springframework:spring-context dependency-version: 6.1.20 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.tomcat:tomcat-catalina dependency-version: 9.0.112 dependency-type: direct:production dependency-group: maven - dependency-name: com.thoughtworks.xstream:xstream dependency-version: 1.4.21 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.tomcat:tomcat-catalina dependency-version: 11.0.14 dependency-type: direct:production dependency-group: maven - dependency-name: commons-fileupload:commons-fileupload dependency-version: 1.6.0 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.tomcat:tomcat-catalina dependency-version: 9.0.112 dependency-type: direct:production dependency-group: maven - dependency-name: commons-fileupload:commons-fileupload dependency-version: 1.6.0 dependency-type: direct:production dependency-group: maven - dependency-name: commons-fileupload:commons-fileupload dependency-version: 1.6.0 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.tomcat:tomcat-catalina dependency-version: 9.0.112 dependency-type: direct:production dependency-group: maven - dependency-name: commons-fileupload:commons-fileupload dependency-version: 1.6.0 dependency-type: direct:production dependency-group: maven - dependency-name: com.squareup.okhttp3:okhttp dependency-version: 4.9.2 dependency-type: direct:production dependency-group: maven - dependency-name: org.springframework:spring-core dependency-version: 6.2.11 dependency-type: direct:production dependency-group: maven - dependency-name: org.mozilla:rhino dependency-version: 1.7.14.1 dependency-type: direct:production dependency-group: maven - dependency-name: org.springframework:spring-context dependency-version: 6.1.20 dependency-type: direct:production dependency-group: maven - dependency-name: com.alibaba:fastjson dependency-version: 1.2.83 dependency-type: direct:production dependency-group: maven - dependency-name: com.alibaba:fastjson dependency-version: 1.2.83 dependency-type: direct:production dependency-group: maven - dependency-name: com.thoughtworks.xstream:xstream dependency-version: 1.4.21 dependency-type: direct:production dependency-group: maven - dependency-name: org.jdom:jdom2 dependency-version: 2.0.6.1 dependency-type: direct:production dependency-group: maven - dependency-name: com.thoughtworks.xstream:xstream dependency-version: 1.4.21 dependency-type: direct:production dependency-group: maven ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the maven group with 3 updates in the /SecVulns/VulnCore/Command directory: org.springframework:spring-core, commons-io:commons-io and org.apache.commons:commons-lang3.
Bumps the maven group with 1 update in the /SecVulns/VulnCore/Expression/ELAttack directory: org.apache.logging.log4j:log4j-core.
Bumps the maven group with 3 updates in the /SecVulns/VulnCore/Expression/OGNLAttack directory: org.springframework:spring-core, commons-io:commons-io and org.apache.commons:commons-lang3.
Bumps the maven group with 1 update in the /SecVulns/VulnCore/FilesOperations directory: commons-io:commons-io.
Bumps the maven group with 1 update in the /SecVulns/VulnCore/Inject/SQL directory: com.microsoft.sqlserver:mssql-jdbc.
Bumps the maven group with 1 update in the /SecVulns/VulnCore/JDBCAttack directory: org.springframework:spring-context.
Bumps the maven group with 2 updates in the /SecVulns/VulnCore/JNDIAttack directory: org.apache.tomcat:tomcat-catalina and com.thoughtworks.xstream:xstream.
Bumps the maven group with 1 update in the /SecVulns/VulnCore/MemShellAndRceEcho/JakartaTomcatDemo directory: org.apache.tomcat:tomcat-catalina.
Bumps the maven group with 1 update in the /SecVulns/VulnCore/MemShellAndRceEcho/JavaxJettyDemo directory: commons-fileupload:commons-fileupload.
Bumps the maven group with 2 updates in the /SecVulns/VulnCore/MemShellAndRceEcho/JavaxTomcatDemo directory: org.apache.tomcat:tomcat-catalina and commons-fileupload:commons-fileupload.
Bumps the maven group with 1 update in the /SecVulns/VulnCore/MemShellAndRceEcho/LowTomcatDemo directory: commons-fileupload:commons-fileupload.
Bumps the maven group with 1 update in the /SecVulns/VulnCore/MemShellAndRceEcho/OSEcho directory: org.apache.tomcat:tomcat-catalina.
Bumps the maven group with 1 update in the /SecVulns/VulnCore/MemShellAndRceEcho/ResinDemo directory: commons-fileupload:commons-fileupload.
Bumps the maven group with 1 update in the /SecVulns/VulnCore/SSRF directory: com.squareup.okhttp3:okhttp.
Bumps the maven group with 2 updates in the /SecVulns/VulnCore/Serialization/ClassLoad directory: org.springframework:spring-core and org.mozilla:rhino.
Bumps the maven group with 1 update in the /SecVulns/VulnCore/Serialization/ConstructorEXP directory: org.springframework:spring-context.
Bumps the maven group with 1 update in the /SecVulns/VulnCore/Serialization/FastjsonDemo directory: com.alibaba:fastjson.
Bumps the maven group with 1 update in the /SecVulns/VulnCore/Serialization/SnakeyamlDemo directory: com.alibaba:fastjson.
Bumps the maven group with 1 update in the /SecVulns/VulnCore/Serialization/XMLSerialization/XStreamAttack directory: com.thoughtworks.xstream:xstream.
Bumps the maven group with 1 update in the /SecVulns/VulnCore/XXE directory: org.jdom:jdom2.
Bumps the maven group with 1 update in the /Utils directory: com.thoughtworks.xstream:xstream.
Updates
org.springframework:spring-corefrom 5.3.18 to 6.2.11Release notes
Sourced from org.springframework:spring-core's releases.
... (truncated)
Commits
4c13425Release v6.2.11d17601eUpgrade to Undertow 2.3.19, RxJava 3.1.11, Aalto 1.3.35b38761Clarify intended nestedTransactionAllowed default in JpaTransactionManager0e3e34bFind annotations on parameters in overridden non-public methods4745c7cName local variables consistently275fb52Upgrade to Reactor 2024.0.10 and Micrometer 1.14.117f9aa39Polishingc788554Avoid thread pinning in SseEmitter, ResponseBodyEmitter9e8c640Make JsonPathAssertions#isEqualTo parameter nullableebb8e34Upgrade to Jetty 12.0.26, Jetty Reactive HttpClient 4.0.11, Netty 4.1.127, Ht...Updates
commons-io:commons-iofrom 2.2 to 2.14.0Updates
org.apache.commons:commons-lang3from 3.12.0 to 3.18.0Updates
org.apache.logging.log4j:log4j-corefrom 2.14.1 to 2.25.3Updates
org.springframework:spring-corefrom 5.3.18 to 6.2.11Release notes
Sourced from org.springframework:spring-core's releases.
... (truncated)
Commits
4c13425Release v6.2.11d17601eUpgrade to Undertow 2.3.19, RxJava 3.1.11, Aalto 1.3.35b38761Clarify intended nestedTransactionAllowed default in JpaTransactionManager0e3e34bFind annotations on parameters in overridden non-public methods4745c7cName local variables consistently275fb52Upgrade to Reactor 2024.0.10 and Micrometer 1.14.117f9aa39Polishingc788554Avoid thread pinning in SseEmitter, ResponseBodyEmitter9e8c640Make JsonPathAssertions#isEqualTo parameter nullableebb8e34Upgrade to Jetty 12.0.26, Jetty Reactive HttpClient 4.0.11, Netty 4.1.127, Ht...Updates
commons-io:commons-iofrom 2.2 to 2.14.0Updates
org.apache.commons:commons-lang3from 3.12.0 to 3.18.0Updates
commons-io:commons-iofrom 2.2 to 2.14.0Updates
com.microsoft.sqlserver:mssql-jdbcfrom 9.2.1.jre8 to 11.2.0.jre8Release notes
Sourced from com.microsoft.sqlserver:mssql-jdbc's releases.
... (truncated)
Commits
Updates
org.springframework:spring-contextfrom 5.3.28 to 6.1.20Release notes
Sourced from org.springframework:spring-context's releases.
... (truncated)
Commits
1f9c59bRelease v6.1.20edfcc6fMake use of PatternMatchUtils ignoreCase optionf93132bAdd missing@sincetags in PatternMatchUtils6ab4c84Upgrade to Reactor 2023.0.18d5fca0dUpgrade to Jetty 12.0.21, Netty 4.1.121, Apache HttpClient 5.4.4, Checkstyle ...cbb9419Clarify CompositePropertySource behavior for EnumerablePropertySource contract5b5e2b6Fix HttpClient 5.3.x request config compatibilitya5b0399Polishing71f2725Try loadClass on LinkageError in case of same ClassLoader as welldaee9f1Reinstate the @Inject Technology Compatibility Kit (TCK)Updates
org.apache.tomcat:tomcat-catalinafrom 8.5.78 to 9.0.112Updates
com.thoughtworks.xstream:xstreamfrom 1.4.17 to 1.4.21Commits
Updates
org.apache.tomcat:tomcat-catalinafrom 11.0.0-M1 to 11.0.14Updates
commons-fileupload:commons-fileuploadfrom 1.5 to 1.6.0Updates
org.apache.tomcat:tomcat-catalinafrom 8.0.53 to 9.0.112Updates
commons-fileupload:commons-fileuploadfrom 1.5 to 1.6.0Updates
commons-fileupload:commons-fileuploadfrom 1.5 to 1.6.0Updates
org.apache.tomcat:tomcat-catalinafrom 8.5.82 to 9.0.112Updates
commons-fileupload:commons-fileuploadfrom 1.5 to 1.6.0Updates
com.squareup.okhttp3:okhttpfrom 3.14.9 to 4.9.2Changelog
Sourced from com.squareup.okhttp3:okhttp's changelog.
... (truncated)
Commits
3edf17cPrepare for release 4.9.2.262b3cdHandle strict module handling on JDK17 (#6707) (#6742)f574ea2Cherry pick fix for CVE-2021-0341 onto 4.9.x (#6741)1fd7c0aMake it more difficult to accidentally log sensitive headers (#6551) (#6740)b0397cc4.9.x GitHub builds update (#6732)eb5a834Prepare next development version.63dcd95Prepare for release 4.9.1.d2e28abSilently ignore 'bio == null' NullPointerExceptions (#6534)cbeaf8fPrepare for release 4.9.0.8fd74a7Conscrypt 2.5.1 Upgrade (#6263)Updates
org.springframework:spring-corefrom 5.3.18 to 6.2.11Release notes
Sourced from org.springframework:spring-core's releases.
... (truncated)
Commits
4c13425Release v6.2.11d17601eUpgrade to Undertow 2.3.19, RxJava 3.1.11, Aalto 1.3.35b38761Clarify intended nestedTransactionAllowed default in JpaTransactionManager0e3e34bFind annotations on parameters in overridden non-public methods4745c7cName local variables consistently275fb52Upgrade to Reactor 2024.0.10 and Micrometer 1.14.117f9aa39Polishingc788554Avoid thread pinning in SseEmitter, ResponseBodyEmitter9e8c640Make JsonPathAssertions#isEqualTo parameter nullableebb8e34Upgrade to Jetty 12.0.26, Jetty Reactive HttpClient 4.0.11, Netty 4.1.127, Ht...Updates
org.mozilla:rhinofrom 1.7.14 to 1.7.14.1Changelog
Sourced from org.mozilla:rhino's changelog.
Commits
Updates
org.springframework:spring-contextfrom 5.3.28 to 6.1.20Release notes
Sourced from org.springframework:spring-context's releases.
... (truncated)
Commits
1f9c59bRelease v6.1.20edfcc6fMake use of PatternMatchUtils ignoreCase optionf93132bAdd missing@sincetags in PatternMatchUtils6ab4c84Upgrade to Reactor 2023.0.18d5fca0dUpgrade to Jetty 12.0.21, Netty 4.1.121, Apache HttpClient 5.4.4, Checkstyle ...cbb9419Clarify CompositePropertySource behavior for EnumerablePropertySource contract5b5e2b6Fix HttpClient 5.3.x request config compatibilitya5b0399Polishing71f2725Try loadClass on LinkageError in case of same ClassLoader as welldaee9f1Reinstate the @Inject Technology Compatibility Kit (TCK)Updates
com.alibaba:fastjsonfrom 1.2.47 to 1.2.83Release notes
Sourced from com.alibaba:fastjson's releases.
... (truncated)
Commits
26f13f81.2.838f3410fbug fix for autotypecd3c2deimproved jdk8 java.time supportc63866eremove unused import35db4adbug fix for autoType3f009e1Merge pull request #4085 from hengyunabc/fix_setAccessibledd3de5ffix InaccessibleObjectException in jdk17. #4077a234f9aMerge pull request #4084 from alibaba/revert-4078-master0814909Revert "fix InaccessibleObjectException in jdk17. #4077"ab82d0bMerge pull request #4078 from hengyunabc/masterUpdates
com.alibaba:fastjsonfrom 1.2.47 to 1.2.83Release notes
Sourced from com.alibaba:fastjson's releases.