Skip to content

[Snyk] Security upgrade com.google.guava:guava from 26.0-jre to 30.0-android#2243

Merged
jodastephen merged 2 commits intomasterfrom
snyk-fix-97b704b3467869dafc6f54b94b87b43e
Dec 10, 2020
Merged

[Snyk] Security upgrade com.google.guava:guava from 26.0-jre to 30.0-android#2243
jodastephen merged 2 commits intomasterfrom
snyk-fix-97b704b3467869dafc6f54b94b87b43e

Conversation

@snyk-bot
Copy link
Copy Markdown
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • modules/pom.xml

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Upgrade Breaking Change Exploit Maturity
medium severity 561/1000
Why? Recently disclosed, Has a fix available, CVSS 5.5
Information Disclosure
SNYK-JAVA-COMGOOGLEGUAVA-1015415
com.google.guava:guava:
26.0-jre -> 30.0-android
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

@jodastephen jodastephen force-pushed the snyk-fix-97b704b3467869dafc6f54b94b87b43e branch from f392957 to 5e66647 Compare December 10, 2020 13:34
@jodastephen jodastephen merged commit 37b3911 into master Dec 10, 2020
@delete-merged-branch delete-merged-branch bot deleted the snyk-fix-97b704b3467869dafc6f54b94b87b43e branch December 10, 2020 13:47
@jodastephen jodastephen added this to the v2.9 milestone Feb 2, 2021
@jodastephen jodastephen added the dependencies Pull requests that update a dependency file label Feb 2, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants