Skip to content

Update build.gradle, build-info-extractor-gradle:4.24.14 -> 5.2.4#2260

Open
proggga wants to merge 2 commits intolinkedin:mainfrom
proggga:patch-1
Open

Update build.gradle, build-info-extractor-gradle:4.24.14 -> 5.2.4#2260
proggga wants to merge 2 commits intolinkedin:mainfrom
proggga:patch-1

Conversation

@proggga
Copy link
Contributor

@proggga proggga commented Mar 18, 2025

bump build-info-extractor to 5.2.4

Summary

  1. Why: current version have multiple vulnerabilitis
    org.jfrog.buildinfo:build-info-extractor-gradle@4.24.14 → org.jfrog.buildinfo:build-info-api@2.28.8 → com.thoughtworks.xstream:xstream@1.4.17

one of them have xstream with remove code execution
https://security.snyk.io/vuln/SNYK-JAVA-COMTHOUGHTWORKSXSTREAM-1569183
weneed to update gradle, which will update dependecy on build-info-api which is not using xstream at all

  1. What: bupm versoin

Expected Behavior

no changes

Actual Behavior

no changes

Categorization

  • documentation
  • bugfix
  • new feature
  • refactor
  • security/CVE
  • other

proggga added 2 commits March 18, 2025 14:52
bump build-info-extractor to 5.2.4
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant