Remediate guava dependency vulnerability and cleanup 'documentdb-bulkexecutor'
Change details
- excluded unused dependency
documentdb-bulkexecutor
to removeguava:24.1.1-jre
version with vulnerabilities
Changes in:
-
GCP -
Azure -
AWS -
IBM
Merge request reports
Activity
changed milestone to %M21 - Release 0.24
added Azure Vulnerability Management labels
assigned to @thulasi_dass
Hello @Srinivasan_Narayanan - Kindly review and approve the vulnerability remediation MR (Azure only changes).
- Pipeline all jobs are passed
- Verified the remediation by
mvn dependency:tree -Dincludes=:guava:::
- Trivy container_scanning job
guava
dependency is not listed in the vulnerability list
cc: @chad @nursheikh @lucynliu
Thanks.
mentioned in commit 6026f214
Please register or sign in to reply