Skip to content

Conversation

@trask
Copy link
Member

@trask trask commented Aug 19, 2025

This does reduce the version of azure-identity from 1.16.3 back to 1.16.2, but I think that's ok given that update was just due to us merging a dependabot PR (#4386), and wasn't part of the original pinning.

Running OWASP on this branch to check: https://github.com/trask/ApplicationInsights-Java/actions/runs/17077701328

@trask
Copy link
Member Author

trask commented Aug 19, 2025

Closing, looks like we do need 1.16.3:

nimbus-jose-jwt-10.0.1.jar/META-INF/maven/com.google.code.gson/gson/pom.xml (pkg:maven/com.google.code.gson/[email protected], cpe:2.3:a:google:gson:2.11.0:*:*:*:*:*:*:*) : CVE-2025-53864

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant