Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade testng in reactive-streams-tck #528

Closed
barambani opened this issue Mar 5, 2021 · 1 comment
Closed

Upgrade testng in reactive-streams-tck #528

barambani opened this issue Mar 5, 2021 · 1 comment

Comments

@barambani
Copy link

Currently reactive-streams-tck is bringing testng at version 7.0.0 that was using a jcommander version (com.beust:jcommander@1.72 ) affected by a security vulnerability

https://snyk.io/vuln/SNYK-JAVA-COMBEUST-174815

please consider updating it.

viktorklang added a commit that referenced this issue Mar 6, 2021
Signed-off-by: Viktor Klang <viktor.klang@gmail.com>
viktorklang added a commit that referenced this issue Mar 6, 2021
Signed-off-by: Viktor Klang <viktor.klang@gmail.com>
viktorklang added a commit that referenced this issue Mar 6, 2021
Signed-off-by: Viktor Klang <viktor.klang@gmail.com>
viktorklang added a commit that referenced this issue Mar 8, 2021
Signed-off-by: Viktor Klang <viktor.klang@gmail.com>
@lukaseder
Copy link

I'm running into this as well:

13:29:51,262 [ERROR] One or more dependencies were identified with vulnerabilities that have a CVSS score greater than or equal to '0.0':
13:29:51,268 [ERROR] bsh-2.0b4.jar: CVE-2016-2510
13:29:51,292 [ERROR] snakeyaml-1.6.jar: CVE-2017-18640

Is there a publication of a new version on the roadmap? 1.0.3 still has the dependency:
https://search.maven.org/artifact/org.reactivestreams/reactive-streams-tck

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants