Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade java-diff-utils 4.0 -> 4.12 #4087

Closed
wants to merge 1 commit into from
Closed

Commits on Sep 14, 2023

  1. Upgrade java-diff-utils 4.0 -> 4.12

    This drops the indirect dependency on `org.eclipse.jgit`, guaranteeing
    that CVE-2023-4759 is mitigated.
    
    Resolves #4081.
    
    See:
    - https://nvd.nist.gov/vuln/detail/CVE-2023-4759
    - https://github.com/java-diff-utils/java-diff-utils/releases/tag/java-diff-utils-parent-4.12
    - java-diff-utils/java-diff-utils@java-diff-utils-4.0...java-diff-utils-parent-4.12
    
    Fixes #4085
    
    FUTURE_COPYBARA_INTEGRATE_REVIEW=#4085 from PicnicSupermarket:sschroevers/upgrade-java-diff-utils bf4e906
    PiperOrigin-RevId: 565083922
    Stephan202 authored and Error Prone Team committed Sep 14, 2023
    Configuration menu
    Copy the full SHA
    36bbe30 View commit details
    Browse the repository at this point in the history