Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump schema-lib from 2.13.1 to 2.13.10 #102

Merged
merged 4 commits into from
Jan 26, 2023
Merged

Bump schema-lib from 2.13.1 to 2.13.10 #102

merged 4 commits into from
Jan 26, 2023

Conversation

big-andy-coates
Copy link
Member

@big-andy-coates big-andy-coates commented Jan 26, 2023

The version of Scala is brought in by a dependency has security vulnerabilities. Force Scala version to 2.13.10

See https://sbom.lift.sonatype.com/report/T1-a0368c8f29fdaa555824-89a20518f39cd-1673481850-0b331e440852477381e481142d50e92c for more info

Reviewer checklist

  • Read the contributing guide
  • PR should be motivated, i.e. what does it fix, why, and if relevant, how
  • Ensure relevant issues are linked (description should include text like "Fixes #")
  • Ensure any appropriate documentation has been added or amended

…cies

- Fixes scala version at `2.13.10`
- Fixes Kotlin version at `1.7.22`, (down from `1.8.0` which isn't supported by CodeQL yet).

Excludes `org.jetbrains.kotlin:kotlin-scripting-jvm` as it has known vulnerabilities
@big-andy-coates big-andy-coates added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Jan 26, 2023
@big-andy-coates big-andy-coates requested a review from a team as a code owner January 26, 2023 17:31
@big-andy-coates big-andy-coates changed the title Force dependency versions to fix security vulnerabilities in dependencies Bump schema-lib from 2.13.1 to 2.13.10 Jan 26, 2023
@coveralls
Copy link

coveralls commented Jan 26, 2023

Coverage Status

Coverage: 94.007%. Remained the same when pulling 282cd1a on security into 1ae3b4a on main.

@big-andy-coates big-andy-coates merged commit b295e5e into main Jan 26, 2023
@big-andy-coates big-andy-coates deleted the security branch January 26, 2023 18:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file java Pull requests that update Java code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants