Skip to content

fix: CVE-2024-47554 vulnerability #887

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wants to merge 1 commit into from

Conversation

gustavonj
Copy link

The following vulnerability is fixed with an upgrade:
-https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-47554

@paulbors
Copy link

paulbors commented Jun 26, 2025

Hey @xeno6696, @kwwall

Can we get this in and release please?

@kwwall
Copy link
Contributor

kwwall commented Jun 26, 2025

I've had this in my personal build on my laptop for maybe 2 weeks or there about. We get Snyk, DependaBot, and other SCA tools notifying us. I've been working to get out a release for a while now, because OSSRH is being shut down on 6/30, so we are racing the clock to get out a release before that happens just in case something goes wrong with the migration or afterwards. There are other updates included as well.

However, since I've already have this in my local pom.xml along with other changes to plugins, etc. I am going to close this without merging it so when I push my changes, it doesn't cause any sort of merge conflict. Hang on to your hats though. We should have a new release out at least by COB Monday, 6/30.

@kwwall kwwall closed this Jun 26, 2025
@paulbors
Copy link

We can wait 4 days :)

Beats having to push a custom artifact into our organization's artifact mirror

@kwwall
Copy link
Contributor

kwwall commented Jun 26, 2025 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants