Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dependencies: upgrade janino dependency to 3.1.12 #941

Merged
merged 3 commits into from
Sep 30, 2024

Conversation

cfkoehler
Copy link
Collaborator

Upgrading janino to mitigate CVE: https://nvd.nist.gov/vuln/detail/CVE-2023-33546 to 3.1.12
More details fromSBOM

Noticed that in the past we tried to remove it but had to revert that change here: 9f789d5

@cfkoehler cfkoehler added the dependencies This updates a dependency version label Sep 19, 2024
@cfkoehler cfkoehler requested a review from jpdahlke September 19, 2024 09:32
@cfkoehler cfkoehler self-assigned this Sep 19, 2024
@cfkoehler cfkoehler changed the title Janino upgrade janino dependency to 3.1.12 Sep 19, 2024
@jpdahlke jpdahlke added this to the v8.13.0 milestone Sep 21, 2024
@jpdahlke jpdahlke changed the title upgrade janino dependency to 3.1.12 dependencies: upgrade janino dependency to 3.1.12 Sep 26, 2024
@jpdahlke jpdahlke added the security There are security/vulnerability implications label Sep 30, 2024
@jpdahlke jpdahlke merged commit 1b514ae into NationalSecurityAgency:main Sep 30, 2024
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies This updates a dependency version security There are security/vulnerability implications
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants