Skip to content

maven dependency updates#106

Merged
mbien merged 1 commit intoapache:masterfrom
mbien:mvn_deps
Dec 11, 2021
Merged

maven dependency updates#106
mbien merged 1 commit intoapache:masterfrom
mbien:mvn_deps

Conversation

@mbien
Copy link
Copy Markdown
Member

@mbien mbien commented Dec 10, 2021

highlights:

  • log4j 2.15.0 (fixes security vulnerability[1][2][3])
  • lucene 9 (artifact name changed)
  • spring security 5.6
  • jquery-ui 1.13 via webjar
  • other minor version bumps

[1] https://www.lunasec.io/docs/blog/log4j-zero-day/
[2] apache/logging-log4j2#608
[3] GHSA-jfh8-c2jp-5v3q

highlights:
 - log4j 2.15.0 (fixes CVE)
 - lucene 9
 - spring security 5.6
 - jquery-ui 1.13 via webjar
 - other minor version bumps
@mbien mbien requested a review from snoopdave December 10, 2021 07:01
Copy link
Copy Markdown
Contributor

@snoopdave snoopdave left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@mbien mbien merged commit e91676c into apache:master Dec 11, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants