Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade maven-assembly-plugin to 3.7.1 - CVE-2023-37460 #674

Conversation

camille-hdl
Copy link
Contributor

see #673, in which I explain that I'm not used to the Java ecosystem and I'm interested in advice on how to solve this correctly if this PR is not the right way.

This bumps plexus-archiver to 4.9.2, which fixes CVE-2023-37460 (starting from 4.8)

see:

@glenrobson
Copy link
Contributor

Thanks @camille-hdl the change looks great. Could you target the pull request to the develop branch? We are currently working on creating a release from that branch rather than the 5.0 release at the moment.

We have a cantaloupe meeting tomorrow which you are welcome to join. Connection details and time can be see on the IIIF calendar: https://iiif.io/community/

@camille-hdl camille-hdl changed the base branch from release/5.0 to develop July 30, 2024 14:29
@camille-hdl camille-hdl changed the base branch from develop to release/5.0 July 30, 2024 14:29
@camille-hdl
Copy link
Contributor Author

@glenrobson it shows a bunch of old commits when I change the base branch of this PR, I'll just branch from develop and do another PR, hold on

@camille-hdl
Copy link
Contributor Author

now done in #675

@glenrobson
Copy link
Contributor

Thanks for making the new pull request.

jcoyne added a commit that referenced this pull request Jul 31, 2024
…ly-plugin-from-develop

Upgrade maven-assembly-plugin to 3.7.1 - CVE-2023-37460 (replaces #674)
@glenrobson
Copy link
Contributor

Closing as we've done this in develop branch now.

@glenrobson glenrobson closed this Jul 31, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants