Skip to content

Conversation

@kotharironak
Copy link
Contributor

  • Upgrade libs to fix vulnerabilities
    Existing synk repot:
Testing /Users/ronak/hypertrace/service-framework...

Tested 73 dependencies for known issues, found 1 issue, 2 vulnerable paths.


Issues with no direct upgrade or patch:
  ✗ Denial of Service (DoS) [Medium Severity][https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038424] in com.fasterxml.jackson.core:jackson-databind@2.12.7.1
    introduced by io.dropwizard.metrics:metrics-servlets@4.2.13 > com.fasterxml.jackson.core:jackson-databind@2.12.7.1 and 1 other path(s)
  This issue was fixed in versions: 2.13.4

Organization:      kotharironak
Package manager:   gradle
Target file:       build.gradle.kts
Project name:      service-framework/platform-service-framework
Open source:       no
Project path:      /Users/ronak/hypertrace/service-framework
Licenses:          enabled

Fixed the above issue.

@github-actions

This comment has been minimized.

@codecov
Copy link

codecov bot commented Feb 21, 2023

Codecov Report

Merging #66 (0b374be) into main (b530956) will not change coverage.
The diff coverage is n/a.

@@            Coverage Diff            @@
##               main      #66   +/-   ##
=========================================
  Coverage     70.57%   70.57%           
  Complexity      106      106           
=========================================
  Files            15       15           
  Lines           588      588           
  Branches         32       32           
=========================================
  Hits            415      415           
  Misses          154      154           
  Partials         19       19           
Flag Coverage Δ
unit 70.57% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

📣 We’re building smart automated test selection to slash your CI/CD build times. Learn more

@kotharironak kotharironak merged commit bab8900 into main Feb 21, 2023
@kotharironak kotharironak deleted the fixed-vuln-issues branch February 21, 2023 14:58
@github-actions
Copy link

Unit Test Results

  9 files  ±0    9 suites  ±0   12s ⏱️ ±0s
31 tests ±0  31 ✔️ ±0  0 💤 ±0  0 ❌ ±0 

Results for commit bab8900. ± Comparison against base commit b530956.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants