Skip to content

📦 Bump versions of multiple dependencies to address vulnerabilities#60

Open
sri-kvmk wants to merge 2 commits into30morefrom
devtask/LINEAJE-TASK-614
Open

📦 Bump versions of multiple dependencies to address vulnerabilities#60
sri-kvmk wants to merge 2 commits into30morefrom
devtask/LINEAJE-TASK-614

Conversation

@sri-kvmk
Copy link
Collaborator

Lineaje has automatically created this pull request to resolve the following CVEs:

Component CVE ID Severity Description
org.apache.logging.log4j:log4j-core:2.14.1 CVE-2021-44228 Critical
org.apache.logging.log4j:log4j-core:2.14.1 CVE-2021-45046 Critical
org.apache.logging.log4j:log4j-core:2.14.1 CVE-2021-45105 Medium
org.apache.logging.log4j:log4j-core:2.14.1 CVE-2021-44832 Medium
com.fasterxml.jackson.core:jackson-databind:2.12.3 CVE-2022-42004 High
com.fasterxml.jackson.core:jackson-databind:2.12.3 CVE-2022-42003 High
com.fasterxml.jackson.core:jackson-databind:2.12.3 CVE-2021-46877 High
com.fasterxml.jackson.core:jackson-databind:2.12.3 CVE-2020-36518 High

You can merge this PR once the tests pass and the changes are reviewed.

Thank you for reviewing the update! 🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant