Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update x-stream to 1.4.16 (from 1.4.15) #655

Closed
wants to merge 3 commits into from

Conversation

sseide
Copy link
Contributor

@sseide sseide commented Apr 6, 2021

Description

security update for com.thoughtworks.xstream:xstream from 1.4.15 to 1.4.16

Motivation and Context

This update fixes the following CVE:

How Has This Been Tested?

Tested with running gradlew test and within our own installation where this library was replaced.

Types of changes

  • Bug fix (non-breaking change which fixes an issue)

Checklist:

  • My code follows the code style of this project.
  • I have updated the documentation accordingly.

@sseide
Copy link
Contributor Author

sseide commented Apr 6, 2021

Somehow unrelated question - the gradle build tools generate a new / updated checksum.xml.
Why does this file contains a reference to xerces:xercesImpl at version 2.9.1 AND 2.12.1? Dependency resolution shows version 2.12.1 only.
Thats the other change for that file after running gradle. It was not me...

@sseide sseide marked this pull request as draft April 6, 2021 17:08
@sseide sseide marked this pull request as ready for review April 6, 2021 20:53
@asfgit asfgit closed this in 18d0a5c Apr 10, 2021
@FSchumacher
Copy link
Contributor

Somehow unrelated question - the gradle build tools generate a new / updated checksum.xml.
Why does this file contains a reference to xerces:xercesImpl at version 2.9.1 AND 2.12.1? Dependency resolution shows version 2.12.1 only.
Thats the other change for that file after running gradle. It was not me...

The 2.9.1 has been probably forgotten to be removed.

@FSchumacher
Copy link
Contributor

Thanks for the PR.

@sseide sseide deleted the update_xstream branch June 7, 2021 08:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants