Skip to content

Comments

bump Apache Tika to 1.24.1#7300

Merged
kcondon merged 2 commits intoIQSS:developfrom
uncch-rdmc:21_bump_tika_1_24_1
Oct 15, 2020
Merged

bump Apache Tika to 1.24.1#7300
kcondon merged 2 commits intoIQSS:developfrom
uncch-rdmc:21_bump_tika_1_24_1

Conversation

@donsizemore
Copy link
Contributor

What this PR does / why we need it: The Apache Tika version in pom.xml is vulnerable to CVE-2020-1950 and CVE-2020-1951

Which issue(s) this PR closes:

Closes #21 aka https://github.com/IQSS/dataverse-security/issues/21

Special notes for your reviewer: none

Suggestions on how to test this: I ran this through unit and integration tests, how better to test?

Does this PR introduce a user interface change? If mockups are available, please link/include them here: no

Is there a release notes update needed for this change?: no

Additional documentation: none

@coveralls
Copy link

coveralls commented Oct 6, 2020

Coverage Status

Coverage remained the same at 19.433% when pulling 798f288 on OdumInstitute:21_bump_tika_1_24_1 into 62b7fdf on IQSS:develop.

Copy link
Member

@qqmyers qqmyers left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Running this with test machines at QDR - haven't seen any issues/differences.

@kcondon kcondon self-assigned this Oct 14, 2020
@kcondon kcondon merged commit 078730d into IQSS:develop Oct 15, 2020
@djbrooke djbrooke added this to the 5.2 milestone Oct 15, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add creative commons license info for CC0

5 participants