Skip to content

security: upgrade com.google.guava:guava to 32.0.0-jre#6069

Merged
funky-eyes merged 2 commits intoapache:2.xfrom
imcmai:oscs_fix_cle5f70au51vtpiu92n0
Nov 25, 2023
Merged

security: upgrade com.google.guava:guava to 32.0.0-jre#6069
funky-eyes merged 2 commits intoapache:2.xfrom
imcmai:oscs_fix_cle5f70au51vtpiu92n0

Conversation

@imcmai
Copy link
Contributor

@imcmai imcmai commented Nov 21, 2023

What happened?

There are 1 security vulnerabilities found in com.google.guava:guava 30.1-jre

What did I do?

Upgrade com.google.guava:guava from 30.1-jre to 32.0.0-jre for vulnerability fix

What did you expect to happen?

Ideally, no insecure libs should be used.

@CLAassistant
Copy link

CLAassistant commented Nov 21, 2023

CLA assistant check
All committers have signed the CLA.

@funky-eyes funky-eyes added this to the 2.x Backlog milestone Nov 21, 2023
@codecov
Copy link

codecov bot commented Nov 21, 2023

Codecov Report

Merging #6069 (ef24ed0) into 2.x (ded33d1) will increase coverage by 0.03%.
The diff coverage is n/a.

❗ Current head ef24ed0 differs from pull request most recent head d3505dc. Consider uploading reports for the commit d3505dc to get more accurate results

Additional details and impacted files

Impacted file tree graph

@@             Coverage Diff              @@
##                2.x    #6069      +/-   ##
============================================
+ Coverage     49.44%   49.48%   +0.03%     
- Complexity     4745     4751       +6     
============================================
  Files           908      908              
  Lines         31354    31354              
  Branches       3777     3777              
============================================
+ Hits          15504    15516      +12     
+ Misses        14309    14306       -3     
+ Partials       1541     1532       -9     

see 4 files with indirect coverage changes

Copy link
Contributor

@funky-eyes funky-eyes left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

请登记pr和作者信息至 https://github.com/seata/seata/tree/2.x/changes 中的2.x.md中
Please register the PR and author information in the 2.x.md file located at https://github.com/seata/seata/tree/2.x/changes

@imcmai imcmai mentioned this pull request Nov 22, 2023
1 task
@imcmai
Copy link
Contributor Author

imcmai commented Nov 22, 2023

请登记pr和作者信息至 https://github.com/seata/seata/tree/2.x/changes 中的2.x.md中 Please register the PR and author information in the 2.x.md file located at https://github.com/seata/seata/tree/2.x/changes

ok

Copy link
Contributor

@funky-eyes funky-eyes left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@funky-eyes funky-eyes changed the title fix(sec): upgrade com.google.guava:guava to 32.0.0-jre security: upgrade com.google.guava:guava to 32.0.0-jre Nov 25, 2023
@funky-eyes funky-eyes merged commit 09097aa into apache:2.x Nov 25, 2023
@funky-eyes funky-eyes modified the milestones: 2.x Backlog, 2.1.0 Nov 25, 2023
YvCeung pushed a commit to YvCeung/incubator-seata that referenced this pull request Dec 25, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Development

Successfully merging this pull request may close these issues.

3 participants