Skip to content
This repository has been archived by the owner on Apr 3, 2023. It is now read-only.

Following dependencies bring security issues #176

Open
vladburian1 opened this issue Jun 9, 2022 · 0 comments
Open

Following dependencies bring security issues #176

vladburian1 opened this issue Jun 9, 2022 · 0 comments

Comments

@vladburian1
Copy link

snyk reports that there are a few security issues in this repo, all of them have Hight level severity. Please upgrade following dependencies

org.springframework:spring-beans
Introduced through
io.testproject:java-sdk@1.3.0-RELEASE
Fixed in
org.springframework:spring-beans@5.2.20, @5.3.18

commons-io:commons-io
Introduced through
io.testproject:java-sdk@1.3.0-RELEASE
Fixed in
commons-io:commons-io@2.7

junit:junit
Introduced through
io.testproject:java-sdk@1.3.0-RELEASE

org.aspectj:aspectjweaver
Introduced through
io.testproject:java-sdk@1.3.0-RELEASE

commons-beanutils:commons-beanutils
Introduced through
io.testproject:java-sdk@1.3.0-RELEASE
Fixed in
commons-beanutils:commons-beanutils@1.9.4

org.apache.httpcomponents:httpclient
Introduced through
io.testproject:java-sdk@1.3.0-RELEASE
Fixed in
org.apache.httpcomponents:httpclient@4.5.13

org.springframework:spring-beans
Introduced through
io.testproject:java-sdk@1.3.0-RELEASE
Fixed in
org.springframework:spring-beans@5.2.22.RELEASE, @5.3.20

org.springframework:spring-expression
Introduced through
io.testproject:java-sdk@1.3.0-RELEASE
Fixed in
org.springframework:spring-expression@5.3.17, @5.2.20.RELEASE

org.springframework:spring-core
Introduced through
io.testproject:java-sdk@1.3.0-RELEASE
Fixed in
org.springframework:spring-core@5.2.19.RELEASE, @5.3.14

org.springframework:spring-core
Introduced through
io.testproject:java-sdk@1.3.0-RELEASE
Fixed in
org.springframework:spring-core@5.3.12, @5.2.18

@vladburian1 vladburian1 changed the title Please update following dependencies as they bring security issues Following dependencies bring security issues Jun 9, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant