Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade java-diff-utils 4.0 -> 4.12 #4087

Closed
wants to merge 1 commit into from
Closed

Conversation

copybara-service[bot]
Copy link
Contributor

Upgrade java-diff-utils 4.0 -> 4.12

This drops the indirect dependency on org.eclipse.jgit, guaranteeing
that CVE-2023-4759 is mitigated.

Resolves #4081.

See:

Fixes #4085

FUTURE_COPYBARA_INTEGRATE_REVIEW=#4085 from PicnicSupermarket:sschroevers/upgrade-java-diff-utils bf4e906

@copybara-service copybara-service bot force-pushed the test_565083922 branch 2 times, most recently from a4d38d2 to 84c7705 Compare September 13, 2023 18:22
This drops the indirect dependency on `org.eclipse.jgit`, guaranteeing
that CVE-2023-4759 is mitigated.

Resolves #4081.

See:
- https://nvd.nist.gov/vuln/detail/CVE-2023-4759
- https://github.com/java-diff-utils/java-diff-utils/releases/tag/java-diff-utils-parent-4.12
- java-diff-utils/java-diff-utils@java-diff-utils-4.0...java-diff-utils-parent-4.12

Fixes #4085

FUTURE_COPYBARA_INTEGRATE_REVIEW=#4085 from PicnicSupermarket:sschroevers/upgrade-java-diff-utils bf4e906
PiperOrigin-RevId: 565083922
@sathish-kumar-subramani

Hi @cushon @graememorgan,

Can we get this merged?

@graememorgan
Copy link
Member

Hi @cushon @graememorgan,

Can we get this merged?

Looks like the same thing has already been done? d7f112e

@sathish-kumar-subramani

d7f112e

oh yes. Can you please trigger a release to include this fix?

@cushon
Copy link
Collaborator

cushon commented Sep 20, 2023

d7f112e

oh yes. Can you please trigger a release to include this fix?

I'm going to try to get a release out in the next week or so.

@copybara-service copybara-service bot closed this Sep 21, 2023
@copybara-service copybara-service bot deleted the test_565083922 branch September 21, 2023 16:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Update io.github.java-diff-utils:java-diff-utils to 4.4 or higher
4 participants