Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: bump commons-compress from 1.25.0 to 1.26.0 to fix CVE-2024-25710 and CVE-2024-26308 #6492

Merged
merged 1 commit into from Mar 12, 2024

Conversation

jmonsma
Copy link
Contributor

@jmonsma jmonsma commented Feb 28, 2024

Fixes Issue

CVE-2024-25710
CVE-2024-26308

Description of Change

Bumped package version from 1.25.0 to 1.26.0 that fixes the CVE's

Have test cases been added to cover the new functionality?

No

@jmonsma jmonsma changed the title Bump commons-compress from 1.25.0 to 1.26.0 to fix CVE-2024-25710 and CVE-2024-26308 fixL Bump commons-compress from 1.25.0 to 1.26.0 to fix CVE-2024-25710 and CVE-2024-26308 Feb 28, 2024
@jmonsma jmonsma changed the title fixL Bump commons-compress from 1.25.0 to 1.26.0 to fix CVE-2024-25710 and CVE-2024-26308 fix: bump commons-compress from 1.25.0 to 1.26.0 to fix CVE-2024-25710 and CVE-2024-26308 Feb 28, 2024
@aikebah aikebah added this to the 9.0.10 milestone Mar 10, 2024
@jeremylong jeremylong merged commit 04aff68 into jeremylong:main Mar 12, 2024
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants