Skip to content

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Jul 31, 2025

Bumps junit:junit from 4.13-beta-3 to 4.13.1.

Release notes

Sourced from junit:junit's releases.

JUnit 4.13.1

Please refer to the release notes for details.

JUnit 4.13

Please refer to the release notes for details.

JUnit 4.13 RC 2

Please refer to the release notes for details.

JUnit 4.13 RC 1

Please refer to the release notes for details.

Changelog

Sourced from junit:junit's changelog.

Summary of changes in version 4.13.1

Rules

Security fix: TemporaryFolder now limits access to temporary folders on Java 1.7 or later

A local information disclosure vulnerability in TemporaryFolder has been fixed. See the published security advisory for details.

Test Runners

[Pull request #1669:](junit-team/junit#1669) Make FrameworkField constructor public

Prior to this change, custom runners could make FrameworkMethod instances, but not FrameworkField instances. This small change allows for both now, because FrameworkField's constructor has been promoted from package-private to public.

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [junit:junit](https://github.com/junit-team/junit4) from 4.13-beta-3 to 4.13.1.
- [Release notes](https://github.com/junit-team/junit4/releases)
- [Changelog](https://github.com/junit-team/junit4/blob/main/doc/ReleaseNotes4.13.1.md)
- [Commits](https://github.com/junit-team/junit4/commits/r4.13.1)

---
updated-dependencies:
- dependency-name: junit:junit
  dependency-version: 4.13.1
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jul 31, 2025
@jpeaks-eroad
Copy link

Logo
Checkmarx One – Scan Summary & Details2aee4908-5119-4623-9cec-7d5cbcee4348

New Issues (1)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
LOW Unpinned Actions Full Length Commit SHA /stale_issue.yml: 13
detailsPinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA help...
ID: t7QLW7aAeEY99HHKqLRYUX2tA9o%3D
Fixed Issues (39)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
HIGH CVE-2018-1000180 Gradle-org.bouncycastle:bcprov-jdk15on-1.56
HIGH CVE-2018-1000613 Gradle-org.bouncycastle:bcprov-jdk15on-1.56
HIGH CVE-2019-17359 Gradle-org.bouncycastle:bcprov-jdk15on-1.56
HIGH CVE-2021-35515 Gradle-org.apache.commons:commons-compress-1.12
HIGH CVE-2021-35516 Gradle-org.apache.commons:commons-compress-1.12
HIGH CVE-2021-35517 Gradle-org.apache.commons:commons-compress-1.12
HIGH CVE-2021-36090 Gradle-org.apache.commons:commons-compress-1.12
HIGH CVE-2021-40828 Maven-software.amazon.awssdk.crt:aws-crt-0.6.5
HIGH CVE-2021-40829 Maven-software.amazon.awssdk.crt:aws-crt-0.6.5
HIGH CVE-2021-40830 Maven-software.amazon.awssdk.crt:aws-crt-0.6.5
HIGH CVE-2021-40831 Maven-software.amazon.awssdk.crt:aws-crt-0.6.5
HIGH CVE-2022-25647 Gradle-com.google.code.gson:gson-2.8.5
HIGH CVE-2022-3171 Gradle-com.google.protobuf:protobuf-java-3.10.0
HIGH CVE-2022-3509 Gradle-com.google.protobuf:protobuf-java-3.10.0
HIGH Cxa9261daf-3755 Gradle-org.bouncycastle:bcprov-jdk15on-1.56
HIGH Cxdfe95b9f-ea87 Gradle-org.jetbrains.kotlin:kotlin-compiler-embeddable-1.3.72
MEDIUM Absolute_Path_Traversal /samples/Identity/src/main/java/identity/FleetProvisioningSample.java: 206
MEDIUM Absolute_Path_Traversal /samples/Greengrass/src/main/java/greengrass/BasicDiscovery.java: 138
MEDIUM Absolute_Path_Traversal /samples/Greengrass/src/main/java/greengrass/BasicDiscovery.java: 138
MEDIUM Absolute_Path_Traversal /samples/Greengrass/src/main/java/greengrass/BasicDiscovery.java: 138
MEDIUM CVE-2018-11771 Gradle-org.apache.commons:commons-compress-1.12
MEDIUM CVE-2018-1324 Gradle-org.apache.commons:commons-compress-1.12
MEDIUM CVE-2020-13956 Gradle-org.apache.httpcomponents:httpclient-4.5.6
MEDIUM CVE-2020-15250 Gradle-junit:junit-4.12
MEDIUM CVE-2020-15250 Gradle-junit:junit-4.13
MEDIUM CVE-2020-15250 Maven-junit:junit-4.13-beta-3
MEDIUM CVE-2020-15522 Gradle-org.bouncycastle:bcprov-jdk15on-1.56
MEDIUM CVE-2020-17521 Gradle-org.codehaus.groovy:groovy-all-2.4.15
MEDIUM CVE-2020-26939 Gradle-org.bouncycastle:bcprov-jdk15on-1.56
MEDIUM CVE-2020-29582 Gradle-org.jetbrains.kotlin:kotlin-compiler-embeddable-1.3.72
MEDIUM CVE-2021-22569 Gradle-com.google.protobuf:protobuf-java-3.10.0
MEDIUM Unchecked_Input_for_Loop_Condition /samples/PubSubStress/src/main/java/pubsubstress/PubSubStress.java: 314
MEDIUM Unchecked_Input_for_Loop_Condition /samples/PubSubStress/src/main/java/pubsubstress/PubSubStress.java: 314
MEDIUM Unchecked_Input_for_Loop_Condition /samples/PubSubStress/src/main/java/pubsubstress/PubSubStress.java: 314
MEDIUM Unchecked_Input_for_Loop_Condition /samples/BasicPubSub/src/main/java/pubsub/PubSub.java: 201
MEDIUM Unchecked_Input_for_Loop_Condition /samples/RawPubSub/src/main/java/rawpubsub/RawPubSub.java: 144
LOW CVE-2020-8908 Gradle-com.google.guava:guava-28.1-jre
LOW Cxeb68d52e-5509 Gradle-commons-codec:commons-codec-1.10
LOW Heap_Inspection /samples/RawPubSub/src/main/java/rawpubsub/RawPubSub.java: 37

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant