Skip to content

Upgrade maven-artifact to latest patch to remove transitive CVE for #62#364

Open
rhanton wants to merge 1 commit intoflamingock:developfrom
rhanton:develop
Open

Upgrade maven-artifact to latest patch to remove transitive CVE for #62#364
rhanton wants to merge 1 commit intoflamingock:developfrom
rhanton:develop

Conversation

@rhanton
Copy link

@rhanton rhanton commented Oct 31, 2025

Issue reference

#62

Documentation PR reference

It did not appear that we list dependency info in the documentation today, so no PR made.

Description and context

Needed to upgrade this standard dependency to resolve transitive dependency on old apache commons-lang3 subject to https://www.cve.org/CVERecord?id=CVE-2025-48924

Benefits

Now using latest 3.x version of maven library.

Possible Drawbacks

Should not be any noticeable drawbacks.

Checklist

@rhanton rhanton requested a review from dieppa as a code owner October 31, 2025 18:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant