Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerable dependencies updates #39

Merged
merged 3 commits into from
Apr 24, 2024
Merged

Conversation

akomii
Copy link
Contributor

@akomii akomii commented Feb 2, 2024

Updated dependencies for CVE mitigation:

Due to the update of Jersey, package "jersey-media-jaxb" has been added to ensure continued Jaxb support

… mitigate CVE-2023-40167

- as a result, updated jersey dependency from 2.30.1 to 2.41 (also to mitigate CVE-2021-28168)
- added jaxb support module for jersey
@akomii akomii requested a review from rwm February 2, 2024 09:30
@akomii akomii self-assigned this Feb 2, 2024
@rwm rwm merged commit 460277d into master Apr 24, 2024
3 checks passed
@rwm rwm deleted the vulnerable-dependencies-updates branch April 24, 2024 07:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

2 participants