Skip to content

Commit fd0b962

Browse files
committed
Bump com.upokecenter:cbor dependency to minimum version 4.5.2
Version 4.0.1 has known vulnerabilities and gets resolved to by transitive exact-version dependencies; this forces a minimum version despite those exact-version transitive dependencies. See: GHSA-fj2w-wfgv-mwq6
1 parent 14eef3d commit fd0b962

File tree

2 files changed

+9
-1
lines changed

2 files changed

+9
-1
lines changed

NEWS

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,11 @@
1+
== Version 1.12.2 (unreleased) ==
2+
3+
Fixes:
4+
5+
* `com.upokecenter:cbor` dependency bumped to minimum version 4.5.1 due to a
6+
known vulnerability, see: https://github.com/advisories/GHSA-fj2w-wfgv-mwq6
7+
8+
19
== Version 1.12.1 ==
210

311
Fixes:

build.gradle

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ dependencies {
5151
api('com.fasterxml.jackson.dataformat:jackson-dataformat-cbor:[2.11.0,3)')
5252
api('com.fasterxml.jackson.datatype:jackson-datatype-jdk8:[2.11.0,3)')
5353
api('com.google.guava:guava:[24.1.1,31)')
54-
api('com.upokecenter:cbor:[4.0.1,5)')
54+
api('com.upokecenter:cbor:[4.5.1,5)')
5555
api('javax.ws.rs:javax.ws.rs-api:[2.1,3)')
5656
api('javax.xml.bind:jaxb-api:[2.3.0,3)')
5757
api('junit:junit:[4.12,5)')

0 commit comments

Comments
 (0)