Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RUN-983: Package Updates to address new CVEs #7787

Merged
merged 2 commits into from
Jul 29, 2022

Conversation

ahormazabal
Copy link
Contributor

@ahormazabal ahormazabal commented Jun 28, 2022

This PR updates the following dependencies reported by twistlock scan:

Also includes the following additional updates:

  • grails -> 5.1.7 to 5.1.8
  • grails gradle plugin -> 5.1.2 to 5.1.5

@mergify mergify bot added the 4.x label Jun 28, 2022
@ahormazabal
Copy link
Contributor Author

At this point this PR manages to create a war file that passes the twistlock scan. However, the spring upgrade to 5.3.21 produces a boot error and some test failures which i haven´t been able to fix yet.
Also this liquibase issue is causing problem with some tests and h2 database.

@fdevans fdevans changed the title RUN-983: Upgrade dependency versions to address CVEs RUN-983: Package Updates to address new CVEs Jul 19, 2022
@ahormazabal ahormazabal added this to the 4.5.0 milestone Jul 27, 2022
@ahormazabal ahormazabal marked this pull request as ready for review July 27, 2022 18:25
@ehe-pd ehe-pd self-requested a review July 28, 2022 16:48
Copy link
Contributor

@ehe-pd ehe-pd left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Merge until the liquidbase issue is solved.

@ehe-pd ehe-pd self-requested a review July 28, 2022 16:59
@ahormazabal ahormazabal merged commit 79685f5 into main Jul 29, 2022
@ahormazabal ahormazabal deleted the RUN-983-version-upgrades branch July 29, 2022 00:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants