Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update build.gradle, build-info-extractor-gradle:4.24.14 -> 5.2.4 #2260

Open
wants to merge 2 commits into
base: main
Choose a base branch
from

Conversation

proggga
Copy link
Contributor

@proggga proggga commented Mar 18, 2025

bump build-info-extractor to 5.2.4

Summary

  1. Why: current version have multiple vulnerabilitis
    org.jfrog.buildinfo:[email protected] → org.jfrog.buildinfo:[email protected] → com.thoughtworks.xstream:[email protected]

one of them have xstream with remove code execution
https://security.snyk.io/vuln/SNYK-JAVA-COMTHOUGHTWORKSXSTREAM-1569183
weneed to update gradle, which will update dependecy on build-info-api which is not using xstream at all

  1. What: bupm versoin

Expected Behavior

no changes

Actual Behavior

no changes

Categorization

  • documentation
  • bugfix
  • new feature
  • refactor
  • security/CVE
  • other

proggga added 2 commits March 18, 2025 14:52
bump build-info-extractor to 5.2.4
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant