Skip to content

Conversation

@andybharness
Copy link
Contributor

Update various dependencies to remove the following CVEs

commons-lang3-3.14.0.jar (pkg:maven/org.apache.commons/[email protected], cpe:2.3:a:apache:commons_lang:3.14.0:*:*:*:*:*:*:*) : CVE-2025-48924

gson-2.10.jar (pkg:maven/com.google.code.gson/[email protected], cpe:2.3:a:google:gson:2.10:*:*:*:*:*:*:*) : CVE-2025-53864

gson-2.11.0.jar (pkg:maven/com.google.code.gson/[email protected], cpe:2.3:a:google:gson:2.11.0:*:*:*:*:*:*:*) : CVE-2025-53864

logback-core-1.3.14.jar (pkg:maven/ch.qos.logback/[email protected], cpe:2.3:a:qos:logback:1.3.14:*:*:*:*:*:*:*) : CVE-2024-12798, CVE-2024-12801

@andybharness andybharness marked this pull request as ready for review August 11, 2025 09:55
@andybharness andybharness merged commit 313989d into main Aug 11, 2025
2 checks passed
@andybharness andybharness deleted the FFM-12578-fix-cves branch August 11, 2025 09:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant