Skip to content

Conversation

@r-sidd
Copy link
Contributor

@r-sidd r-sidd commented Oct 10, 2024

What is the purpose of the change

Bump commons-io from 2.11.0 to 2.17.0

Brief change log

Commons-io version 2.11.0 has a direct vulnerability and bumping it to the newer version (2.17.0) will remediate this finding.

Direct vulnerabilities:
CVE-2024-47554

Package details:
https://mvnrepository.com/artifact/commons-io/commons-io/2.17.0

Verifying this change

This change is a trivial rework / code cleanup without any test coverage.

Does this pull request potentially affect one of the following parts:

  • Dependencies (does it add or upgrade a dependency): yes
  • The public API, i.e., is any changes to the CustomResourceDescriptors: no
  • Core observer or reconciler logic that is regularly executed: no

Documentation

  • Does this pull request introduce a new feature? no
  • If yes, how is the feature documented? not applicable

@1996fanrui 1996fanrui self-assigned this Oct 12, 2024
Copy link
Member

@1996fanrui 1996fanrui left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the contribution!

LGTM assuming the CI is green.

@1996fanrui 1996fanrui merged commit 29b9c68 into apache:main Oct 12, 2024
233 checks passed
@r-sidd
Copy link
Contributor Author

r-sidd commented Oct 12, 2024

Thanks for the contribution!

LGTM assuming the CI is green.

Cool, thanks 😄

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants