AbsaOSS / AbsaOSS/hyperdrive-trigger

Dependency Updates

未关闭
#813 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
enhancement
主要语言
TypeScript
星标
8
派生
5
PR 合并指标
30 天内没有已合并 PR

描述

## Background
List of vulnerabilities and their respective patches:
```
-Vulnerability: apache commons text remote code execution (cve-2022-42889)
Dependency: commons-text-1.9.jar
Fix version: 1.10.0
-Vulnerability: spring framework security bypass (cve-2023-20860)
Dependency: spring-core-5.3.18.jar
Fix version: 5.3.26
-Vulnerability: spring security authorization bypass
Dependency: spring-security-core-5.6.1.jar
Fix version: 5.6.9

```
## Proposed Solution [Optional]
Solution Ideas:
1. Patch vulnerable dependencies

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。