Skip to content

Conversation

@dondonz
Copy link
Member

@dondonz dondonz commented Aug 2, 2023

Update Guava ahead of patch release

Some security scanners incorrectly flagged the older version as vulnerable #3263

Note that the graphql-java was never vulnerable. We shade in selected classes which are not related to the vulnerability. This is an update to keep security scanners happy.

@dondonz dondonz added this to the 20.5 milestone Aug 2, 2023
@bbakerman bbakerman merged commit abfefc6 into 20.x Aug 3, 2023
@dondonz dondonz deleted the 20.x-guava-update branch August 15, 2023 06:11
dondonz pushed a commit that referenced this pull request Aug 29, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants