Skip to content

Conversation

@sgrampone
Copy link
Contributor

@sgrampone sgrampone commented Oct 13, 2025

Issue:206684
Bump poi-ooxml from version 5.2.2 to version 5.4.1 (latest)
Bump poi-scratchpad from version 5.2.2 to version 5.4.1 (latest)

CVE-2025-31672

Fix transitive commons-compress CVEs

CVE-2024-26308
CVE-2024-25710

#GXSEC

@sgrampone sgrampone requested a review from iroqueta October 13, 2025 16:57
@genexusbot
Copy link
Collaborator

Cherry pick to beta failed, 1 conflicted file in commit 5305c43
  • pom.xml

@sgrampone sgrampone added the dependencies Pull requests that update a dependency file label Oct 13, 2025
@genexusbot
Copy link
Collaborator

Manual cherry pick to beta success

@sgrampone sgrampone merged commit 6635ed9 into master Oct 21, 2025
9 checks passed
@sgrampone sgrampone deleted the fix/bump-poi-ooxml branch October 21, 2025 13:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bot closed dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants