Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrading json-flattener version to latest 0.16.4 version #1223

Merged
merged 1 commit into from
Aug 1, 2023

Conversation

bhavikp19
Copy link
Contributor

@bhavikp19 bhavikp19 commented Aug 1, 2023

Thanks for contributing.

Description

Upgraded json-flattener dependency to latest version 0.16.4 to remove the critical vulnerability in 0.8.1 version from commons-text version 1.8.0

Testing

Did you add a unit test? No since this is dependency upgrade so no new unit test case is required.

@jtablesaw jtablesaw deleted a comment from frankwondon Aug 1, 2023
@benmccann benmccann merged commit 50cb481 into jtablesaw:java-8 Aug 1, 2023
9 of 10 checks passed
@benmccann
Copy link
Collaborator

@bhavikp19 why did you send this against java 8 branch? It will never get released that way. Can you send it against the master branch instead?

@bhavikp19
Copy link
Contributor Author

@bhavikp19 why did you send this against java 8 branch? It will never get released that way.

@benmccann according to this discussion #1201 I figured out that it will be long before there will be release from master branch and we needed this fix urgently because we are currently using version 0.43.1. I thought there would be another 0.43.2 release from java 8 branch looking at the <version>0.43.2-SNAPSHOT</version> in pom.xml. Is there plan to release 0.43.2 from java8 branch just for the critical vulnerability fixes?

Can you send it against the master branch instead?

I am happy to send another PR for master branch if that is what is required for this to be released. Do you know when we can have the release with this fix either way?

@bhavikp19
Copy link
Contributor Author

bhavikp19 commented Aug 1, 2023

Cherry picked merge commit 50cb481 on to master branch and PR is raised here : #1224

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants