Skip to content

Upgrade quartz to 2.4.0-rc2 to fix CVE-2023-39017#12743

Closed
xiangfu0 wants to merge 1 commit intoapache:masterfrom
xiangfu0:upgrade-quartz-2.4.0-rc2
Closed

Upgrade quartz to 2.4.0-rc2 to fix CVE-2023-39017#12743
xiangfu0 wants to merge 1 commit intoapache:masterfrom
xiangfu0:upgrade-quartz-2.4.0-rc2

Conversation

@xiangfu0
Copy link
Contributor

Upgrade quartz to 2.4.0-rc2 to fix CVE-2023-39017

@xiangfu0 xiangfu0 added the dependencies Pull requests that update a dependency file label Mar 28, 2024
@xiangfu0
Copy link
Contributor Author

Ref: quartz-scheduler/quartz#943

@xiangfu0 xiangfu0 added the cve Linked to a published CVE label Mar 28, 2024
@codecov-commenter
Copy link

codecov-commenter commented Mar 28, 2024

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 61.56%. Comparing base (59551e4) to head (b81a354).
Report is 1091 commits behind head on master.

Additional details and impacted files
@@             Coverage Diff              @@
##             master   #12743      +/-   ##
============================================
- Coverage     61.75%   61.56%   -0.20%     
+ Complexity      207      198       -9     
============================================
  Files          2436     2462      +26     
  Lines        133233   134537    +1304     
  Branches      20636    20820     +184     
============================================
+ Hits          82274    82822     +548     
- Misses        44911    45530     +619     
- Partials       6048     6185     +137     
Flag Coverage Δ
custom-integration1 <0.01% <ø> (-0.01%) ⬇️
integration <0.01% <ø> (-0.01%) ⬇️
integration1 <0.01% <ø> (-0.01%) ⬇️
integration2 0.00% <ø> (ø)
java-11 61.51% <ø> (-0.20%) ⬇️
java-21 61.44% <ø> (-0.19%) ⬇️
skip-bytebuffers-false 61.54% <ø> (-0.20%) ⬇️
skip-bytebuffers-true 61.41% <ø> (+33.68%) ⬆️
temurin 61.56% <ø> (-0.20%) ⬇️
unittests 61.55% <ø> (-0.20%) ⬇️
unittests1 46.12% <ø> (-0.77%) ⬇️
unittests2 27.97% <ø> (+0.24%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@Jackie-Jiang
Copy link
Contributor

Do we want to use an rc release as dependency? From the discussion seems the problem is not fixed in 2.4.0-rc2

@xiangfu0 xiangfu0 closed this Aug 30, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cve Linked to a published CVE dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants