apache / apache/maven-changes-plugin

[MCHANGES-455] Freshly released plugin contains CVE-warnings

Open
#384 2 comments 0 reactions 0 assignees View on GitHub
dependencies priority:major
Dominant language
Java
Stars
15
Forks
22
Avg merge
8h 1m
Merged PRs (30d)
3

Description

**[Philipp Ottlinger](https://issues.apache.org/jira/secure/ViewProfile.jspa?name=hugo.hirsch)** opened **[MCHANGES-455](https://issues.apache.org/jira/browse/MCHANGES-455?redirect=false)** and commented

I was happy to find the new RC 3.0.0-M1 ... when I had a look at

 

https://mvnrepository.com/artifact/org.apache.maven.plugins/maven-changes-plugin/3.0.0-M1

I already saw 2 CVE-warnings. Not sure how easy these can be fixed in the next release cycle.

 

Thanks for all your work and help

---

**Affects:** 3.0.0-M1

**Issue Links:**
- [MCHANGES-454](https://issues.apache.org/jira/browse/MCHANGES-454) Deprecate Trac integration

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by inspecting the dependency warnings reported for maven-changes-plugin 3.0.0-M1 on the linked Maven Repository page and compare them with the plugin's release dependency tree. Identify the two CVEs and confirm that a dependency update or exclusion removes them in a subsequent release.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
build-system, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.