Skip to content

[Snyk] Upgrade: com.fasterxml.jackson.datatype:jackson-datatype-jsr310, com.google.guava:guava, commons-io:commons-io, org.apache.commons:commons-exec, org.apache.commons:commons-lang3, org.bitbucket.b_c:jose4j, org.hsqldb:hsqldb, org.postgresql:postgresql, org.projectlombok:lombok, org.springframework.boot:spring-boot-devtools, org.springframework.boot:spring-boot-starter-actuator, org.springframework.boot:spring-boot-starter-data-jpa, org.springframework.boot:spring-boot-starter-security, org.springframework.boot:spring-boot-starter-thymeleaf, org.springframework.boot:spring-boot-starter-undertow, org.springframework.boot:spring-boot-starter-validation, org.springframework.boot:spring-boot-starter-web, org.springframework.retry:spring-retry, org.thymeleaf.extras:thymeleaf-extras-springsecurity5, org.webjars:jquery, org.webjars:bootstrap#79

Open
dstecholution wants to merge 1 commit intodevelopfrom
snyk-upgrade-1b2615c3db77811dcdd3deabeb30fd2f

Conversation

@dstecholution
Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

com.fasterxml.jackson.datatype:jackson-datatype-jsr310
from 2.13.0 to 2.17.2 | 28 versions ahead of your current version | 2 months ago
on 2024-07-05
com.google.guava:guava
from 30.1-jre to 30.1.1-jre | 2 versions ahead of your current version | 3 years ago
on 2021-03-19
commons-io:commons-io
from 2.6 to 2.16.1 | 12 versions ahead of your current version | 5 months ago
on 2024-04-05
org.apache.commons:commons-exec
from 1.3 to 1.4.0 | 1 version ahead of your current version | 8 months ago
on 2024-01-01
org.apache.commons:commons-lang3
from 3.12.0 to 3.16.0 | 4 versions ahead of your current version | a month ago
on 2024-08-01
org.bitbucket.b_c:jose4j
from 0.7.6 to 0.9.6 | 14 versions ahead of your current version | 6 months ago
on 2024-03-06
org.hsqldb:hsqldb
from 2.5.2 to 2.7.3 | 6 versions ahead of your current version | 3 months ago
on 2024-05-31
org.postgresql:postgresql
from 42.3.1 to 42.7.3 | 29 versions ahead of your current version | 6 months ago
on 2024-03-14
org.projectlombok:lombok
from 1.18.22 to 1.18.34 | 6 versions ahead of your current version | 2 months ago
on 2024-06-28
org.springframework.boot:spring-boot-devtools
from 2.6.1 to 2.7.18 | 33 versions ahead of your current version | 10 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter-actuator
from 2.6.1 to 2.7.18 | 33 versions ahead of your current version | 10 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter-data-jpa
from 2.6.1 to 2.7.18 | 33 versions ahead of your current version | 10 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter-security
from 2.6.1 to 2.7.18 | 33 versions ahead of your current version | 10 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter-thymeleaf
from 2.6.1 to 2.7.18 | 33 versions ahead of your current version | 10 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter-undertow
from 2.6.1 to 2.7.18 | 33 versions ahead of your current version | 10 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter-validation
from 2.6.1 to 2.7.18 | 33 versions ahead of your current version | 10 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter-web
from 2.6.1 to 2.7.18 | 33 versions ahead of your current version | 10 months ago
on 2023-11-23
org.springframework.retry:spring-retry
from 1.3.1 to 1.3.4 | 3 versions ahead of your current version | 2 years ago
on 2022-10-14
org.thymeleaf.extras:thymeleaf-extras-springsecurity5
from 3.0.4.RELEASE to 3.1.2.RELEASE | 7 versions ahead of your current version | a year ago
on 2023-07-30
org.webjars:jquery
from 3.5.1 to 3.7.1 | 7 versions ahead of your current version | a year ago
on 2023-08-29
org.webjars:bootstrap
from 3.3.7 to 3.4.1 | 3 versions ahead of your current version | 6 years ago
on 2019-02-19

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
high severity Use of a Broken or Risky Cryptographic Algorithm
SNYK-JAVA-ORGBITBUCKETBC-5488281
539 No Known Exploit
high severity Denial of Service (DoS)
SNYK-JAVA-ORGBITBUCKETBC-6139942
539 Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JAVA-ORGWEBJARS-451164
539 No Known Exploit
medium severity Cross-site Scripting (XSS)
SNYK-JAVA-ORGWEBJARS-451168
539 Proof of Concept
medium severity Cross-site Scripting (XSS)
SNYK-JAVA-ORGWEBJARS-479505
539 No Known Exploit
medium severity Cross-site Scripting (XSS)
SNYK-JAVA-ORGWEBJARS-451160
539 No Known Exploit
medium severity Cross-site Scripting (XSS)
SNYK-JAVA-ORGWEBJARS-451162
539 No Known Exploit
medium severity Directory Traversal
SNYK-JAVA-COMMONSIO-1277109
539 Mature
medium severity Inadequate Encryption Strength
SNYK-JAVA-ORGBITBUCKETBC-6036303
539 No Known Exploit

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade:
  - com.fasterxml.jackson.datatype:jackson-datatype-jsr310 from 2.13.0 to 2.17.2.
    See this package in maven: https://mvnrepository.com/artifact/com.fasterxml.jackson.datatype/jackson-datatype-jsr310/
  - com.google.guava:guava from 30.1-jre to 30.1.1-jre.
    See this package in maven: https://mvnrepository.com/artifact/com.google.guava/guava/
  - commons-io:commons-io from 2.6 to 2.16.1.
    See this package in maven: https://mvnrepository.com/artifact/commons-io/commons-io/
  - org.apache.commons:commons-exec from 1.3 to 1.4.0.
    See this package in maven: https://mvnrepository.com/artifact/org.apache.commons/commons-exec/
  - org.apache.commons:commons-lang3 from 3.12.0 to 3.16.0.
    See this package in maven: https://mvnrepository.com/artifact/org.apache.commons/commons-lang3/
  - org.bitbucket.b_c:jose4j from 0.7.6 to 0.9.6.
    See this package in maven: https://mvnrepository.com/artifact/org.bitbucket.b_c/jose4j/
  - org.hsqldb:hsqldb from 2.5.2 to 2.7.3.
    See this package in maven: https://mvnrepository.com/artifact/org.hsqldb/hsqldb/
  - org.postgresql:postgresql from 42.3.1 to 42.7.3.
    See this package in maven: https://mvnrepository.com/artifact/org.postgresql/postgresql/
  - org.projectlombok:lombok from 1.18.22 to 1.18.34.
    See this package in maven: https://mvnrepository.com/artifact/org.projectlombok/lombok/
  - org.springframework.boot:spring-boot-devtools from 2.6.1 to 2.7.18.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-devtools/
  - org.springframework.boot:spring-boot-starter-actuator from 2.6.1 to 2.7.18.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-actuator/
  - org.springframework.boot:spring-boot-starter-data-jpa from 2.6.1 to 2.7.18.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-data-jpa/
  - org.springframework.boot:spring-boot-starter-security from 2.6.1 to 2.7.18.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-security/
  - org.springframework.boot:spring-boot-starter-thymeleaf from 2.6.1 to 2.7.18.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-thymeleaf/
  - org.springframework.boot:spring-boot-starter-undertow from 2.6.1 to 2.7.18.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-undertow/
  - org.springframework.boot:spring-boot-starter-validation from 2.6.1 to 2.7.18.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-validation/
  - org.springframework.boot:spring-boot-starter-web from 2.6.1 to 2.7.18.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-web/
  - org.springframework.retry:spring-retry from 1.3.1 to 1.3.4.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.retry/spring-retry/
  - org.thymeleaf.extras:thymeleaf-extras-springsecurity5 from 3.0.4.RELEASE to 3.1.2.RELEASE.
    See this package in maven: https://mvnrepository.com/artifact/org.thymeleaf.extras/thymeleaf-extras-springsecurity5/
  - org.webjars:jquery from 3.5.1 to 3.7.1.
    See this package in maven: https://mvnrepository.com/artifact/org.webjars/jquery/
  - org.webjars:bootstrap from 3.3.7 to 3.4.1.
    See this package in maven: https://mvnrepository.com/artifact/org.webjars/bootstrap/

See this project in Snyk:
https://app.snyk.io/org/dstechnolution/project/c7030ff4-fafb-41c4-bd4d-2e0a2d16b9c9?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants