Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Veracode SCA: fixes for vulnerable libraries #1

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

AaronButler-Veracode
Copy link
Owner

This pull request was generated by Veracode SCA to upgrade the following vulnerable libraries:

Type Library From To Breaking
MAVEN org.springframework:spring-web 3.2.15.RELEASE 4.3.0.RC1 No
MAVEN org.springframework:spring-core 3.2.15.RELEASE 5.2.18.RELEASE No
MAVEN commons-fileupload:commons-fileupload 1.3.2 1.3.3 No
MAVEN org.springframework:spring-webmvc 3.2.15.RELEASE 4.3.20.RELEASE No
MAVEN org.springframework:spring-context 3.2.15.RELEASE 5.2.21.RELEASE Yes
MAVEN mysql:mysql-connector-java 5.1.35 8.0.16 Yes

Note that we only upgrade libraries which have versions without any known vulnerabilities. For more information, please see the corresponding Veracode SCA report.

The Breaking column states the likelihood that updating to the recommended library version will cause breaking changes in your code. Please verify that the changes here won't cause issues with your project before merging.

To learn more about this feature, please visit our Help Center for documentation.

Note: this pull request was generated because you or someone else with access to this repository granted Veracode SCA access to submit pull requests.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants