Skip to content

security: exclude dependency on snappy-Java#2317

Merged
yhilmare merged 1 commit intodev/4.2.xfrom
wenmu_424_security_exclude_risky_dependency
May 7, 2024
Merged

security: exclude dependency on snappy-Java#2317
yhilmare merged 1 commit intodev/4.2.xfrom
wenmu_424_security_exclude_risky_dependency

Conversation

@LuckyPickleZZ
Copy link
Copy Markdown
Member

What type of PR is this?

type-security

What this PR does / why we need it:

ODC indirectly relies on the insecure version of org.xerial.snappy:snappy-Java by ob-loader-dumper. It should be excluded.

Which issue(s) this PR fixes:

Fixes #2316

@LuckyPickleZZ LuckyPickleZZ added this to the ODC 4.2.4-bp2 milestone May 6, 2024
@LuckyPickleZZ LuckyPickleZZ self-assigned this May 6, 2024
@LuckyPickleZZ LuckyPickleZZ changed the title security: exclude dependency of insecure version of a component security: exclude dependency on snappy-Java May 6, 2024
Copy link
Copy Markdown
Contributor

@yhilmare yhilmare left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@yhilmare yhilmare merged commit d2d9bd8 into dev/4.2.x May 7, 2024
@yhilmare yhilmare deleted the wenmu_424_security_exclude_risky_dependency branch May 7, 2024 02:10
@LuckyPickleZZ LuckyPickleZZ restored the wenmu_424_security_exclude_risky_dependency branch July 24, 2024 09:01
@LuckyPickleZZ LuckyPickleZZ deleted the wenmu_424_security_exclude_risky_dependency branch July 24, 2024 09:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

2 participants