AbsaOSS / AbsaOSS/hyperdrive-trigger
Dependency Updates
未关闭
enhancement
- 主要语言
- TypeScript
- 星标
- 8
- 派生
- 5
- PR 合并指标
- 30 天内没有已合并 PR
描述
## Background
List of vulnerabilities and their respective patches:
```
-Vulnerability: apache commons text remote code execution (cve-2022-42889)
Dependency: commons-text-1.9.jar
Fix version: 1.10.0
-Vulnerability: spring framework security bypass (cve-2023-20860)
Dependency: spring-core-5.3.18.jar
Fix version: 5.3.26
-Vulnerability: spring security authorization bypass
Dependency: spring-security-core-5.6.1.jar
Fix version: 5.6.9
```
## Proposed Solution [Optional]
Solution Ideas:
1. Patch vulnerable dependencies
贡献指南
评估
这个 Issue 还没有评估数据。