-
Notifications
You must be signed in to change notification settings - Fork 0
[Snyk] Security upgrade com.squareup.retrofit2:retrofit from 2.11.0 to 3.0.0 #416
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
…erabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-COMSQUAREUPOKIO-5773320 - https://snyk.io/vuln/SNYK-JAVA-COMSQUAREUPOKHTTP3-2958044
Reviewer's GuideBumps the Retrofit Maven property in the sample project from 2.11.0 to 3.0.0 to remediate two medium-severity vulnerabilities (DoS and information exposure), entailing a major version upgrade in the POM file. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Snyk has created this PR to fix 2 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
samples/client/petstore/java/retrofit2rx2/pom.xml
Vulnerabilities that will be fixed with an upgrade:
SNYK-JAVA-COMSQUAREUPOKIO-5773320
2.11.0
->3.0.0
Major version upgrade
Proof of Concept
SNYK-JAVA-COMSQUAREUPOKHTTP3-2958044
2.11.0
->3.0.0
Major version upgrade
Proof of Concept
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Denial of Service (DoS)
Summary by Sourcery
Upgrade Retrofit dependency to version 3.0.0 in the sample project to address medium-severity security vulnerabilities.
Bug Fixes:
Build: