Skip to content

Conversation

proggga
Copy link
Contributor

@proggga proggga commented Mar 18, 2025

bump build-info-extractor to 5.2.4

Summary

  1. Why: current version have multiple vulnerabilitis
    org.jfrog.buildinfo:[email protected] → org.jfrog.buildinfo:[email protected] → com.thoughtworks.xstream:[email protected]

one of them have xstream with remove code execution
https://security.snyk.io/vuln/SNYK-JAVA-COMTHOUGHTWORKSXSTREAM-1569183
weneed to update gradle, which will update dependecy on build-info-api which is not using xstream at all

  1. What: bupm versoin

Expected Behavior

no changes

Actual Behavior

no changes

Categorization

  • documentation
  • bugfix
  • new feature
  • refactor
  • security/CVE
  • other

proggga added 2 commits March 18, 2025 14:52
bump build-info-extractor to 5.2.4
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant