Remediate [guava,netty-handler,woodstox-core] dependencies vulnerabilities and cleanup 'documentdb-bulkexecutor'
Change details
- excluded unused dependency
documentdb-bulkexecutor
- upgrade
io.netty:netty-bom
version to4.1.98.Final
- upgrade
woodstox-core
to6.4.0
Changes in:
-
GCP -
Azure -
AWS -
IBM
Edited by Thulasi Dass Subramanian
Merge request reports
Activity
assigned to @thulasi_dass
changed milestone to %M21 - Release 0.24
added MRDependencies Upgrade Vulnerability Management labels
added Azure label
Hello @Srinivasan_Narayanan - Kindly review and approve the vulnerability remediation MR (Azure only changes).
- Pipeline all jobs are passed except `gc-test' which is unrelated to the MR (Azure only changes).
- Verified the remediation by
mvn dependency:tree
- Trivy container_scanning job -
guava, woodstox-core
dependency is not listed in the vulnerability list
cc: @chad @nursheikh @lucynliu
Thanks.
Hello Team, Merging security vulnerability fixes with passing pipelines as per policy.
Thanks.
mentioned in commit 52fc523c
Please register or sign in to reply