Skip to content

Update commons-compress JAR to 1.26#313

Merged
jeff5 merged 2 commits intojython:masterfrom
jeff5:fix-gh310-jar
Feb 26, 2024
Merged

Update commons-compress JAR to 1.26#313
jeff5 merged 2 commits intojython:masterfrom
jeff5:fix-gh310-jar

Conversation

@jeff5
Copy link
Member

@jeff5 jeff5 commented Feb 26, 2024

Fixes #310 (addressing CVE-2024-25710 and CVE-2024-26308). We add commons-io for the first time as commons-compress now depends on it during test_bz2.

Fixes jython#310 (addressing CVE-2024-25710 and CVE-2024-26308). We add
commons-io for the first time as commons-compress now depends on it
during test_bz2.
@jeff5 jeff5 merged commit e61bc77 into jython:master Feb 26, 2024
@jeff5 jeff5 deleted the fix-gh310-jar branch February 27, 2024 07:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CVE-2024-25710 and CVE-2024-26308

1 participant