Skip to content

Upgrade Guava version to address vulnerability #326

@xylo04

Description

@xylo04

The project currently depends on Guava 22.0, which is susceptible to CVE-2018-10237. The dependency should be upgraded to at least >24.1.

Context: I'm on the Apigee (now a Google) team and we're attempting to use google-java-format via Maven plugins. However, no plugin is going to be able to be imported into our artifact server while this vulnerability exists.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions