Skip to content

Conversation

@yashmeet29
Copy link
Collaborator

Describe your changes

In this PR we are updating connectivity-oauth version to 5.21.0 as 5.17.0 has commons-lang3 version 3.17.0 which has security vulnerability. I have also excluded commons-lang3 in connectivity-oauth & commons-codec and added the commons-lang3 library as direct dependency as it is being used in our project.

Any documentation

Type of change

Please delete options that are not relevant.

  • Security Fix in transitive library

Checklist before requesting a review

  • I follow Java Development Guidelines for SAP
  • I have tested the functionality on my cloud environment.
  • I have provided sufficient automated/ unit tests for the code.
  • I have increased or maintained the test coverage.
  • I have ran integration tests on my cloud environment.
  • I have validated blackduck portal for any vulnerability after my commit.

Upload Screenshots/lists of the scenarios tested

  • I have Uploaded Screenshots or added lists of the scenarios tested in description
Screenshot 2025-08-12 at 1 04 41 PM Screenshot 2025-08-12 at 1 15 06 PM

Copy link
Collaborator

@vibhutikumar07 vibhutikumar07 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@vibhutikumar07 vibhutikumar07 merged commit 441c821 into Release_v1.5.0 Aug 12, 2025
2 checks passed
@vibhutikumar07 vibhutikumar07 deleted the dependabotSecurityFixRel branch August 12, 2025 09:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants