Skip to content

Feature/update guava dependency#171

Closed
amy-mccaleb wants to merge 2 commits intoauth0:masterfrom
fidelity-contributions:feature/update_guava_dependency
Closed

Feature/update guava dependency#171
amy-mccaleb wants to merge 2 commits intoauth0:masterfrom
fidelity-contributions:feature/update_guava_dependency

Conversation

@amy-mccaleb
Copy link
Copy Markdown

Changes

Google Guava dependency updated to 31.1 since the 30.0 version is showing as "Out of Date".

References

https://github.com/google/guava

Checklist

@amy-mccaleb amy-mccaleb requested a review from a team as a code owner March 17, 2023 12:15
@brianwarner
Copy link
Copy Markdown

Hi Auth0 team, I'm in the Fidelity OSPO and work with @amy-mccaleb. It looks like the gradelw check is hanging. Is there anything we can do to restart it? @jimmyjames would you know?

Thanks!

@jimmyjames
Copy link
Copy Markdown
Contributor

👋 thanks for the contribution! I'll see why CI is hung and try and bump it, we'll get this change in. Thanks!

@jimmyjames jimmyjames mentioned this pull request May 8, 2023
@brianwarner
Copy link
Copy Markdown

That's great, thanks for having a look!

@bharathkarnam
Copy link
Copy Markdown

bharathkarnam commented Jun 29, 2023

please update Guava dependency to 32.0.1 since there is an owasp CVE-2023-2976, this is currently blocking a lot of builds. Thanks!

@amy-mccaleb
Copy link
Copy Markdown
Author

Closing for now since errors

@colomra1
Copy link
Copy Markdown

Closing for now since errors

Is there a plan to update guava lib ? As someone already mention it contains https://nvd.nist.gov/vuln/detail/CVE-2023-2976 that blocking some projects

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants