Skip to content

Commit d0136e0

Browse files
committed
Update transitive JReleaser dependencies to work around CVEs
1 parent 050f428 commit d0136e0

File tree

1 file changed

+15
-0
lines changed

1 file changed

+15
-0
lines changed

gradle/plugins/publishing/build.gradle.kts

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -8,3 +8,18 @@ dependencies {
88
implementation("junitbuild.base:dsl-extensions")
99
implementation(libs.plugins.jreleaser.markerCoordinates)
1010
}
11+
12+
configurations.configureEach {
13+
resolutionStrategy {
14+
eachDependency {
15+
// Workaround for CVE-2025-4949
16+
if (requested.name == "org.eclipse.jgit") {
17+
useVersion("6.10.1.202505221210-r")
18+
}
19+
// Workaround for CVE-2020-36843
20+
if (requested.name == "sshj") {
21+
useVersion("0.40.0")
22+
}
23+
}
24+
}
25+
}

0 commit comments

Comments
 (0)