Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump Bump ch.qos.logback:logback-classic & Bump ch.qos.logback:logback-core dependencies #3392

Open
domhanak opened this issue Feb 6, 2024 · 3 comments

Comments

@domhanak
Copy link
Contributor

domhanak commented Feb 6, 2024

Description

there are open PR's for this library by dependabot, so that means there is an open CVE for it. We should process it.
This one conerns logback

Goals
Bump ch.qos.logback:logback-core from 1.4.7 to 1.4.14 in /kogito-build/kogito-dependencies-bom
Bump ch.qos.logback:logback-classic from 1.4.7 to 1.4.14 in /kogito-build/kogito-dependencies-bom
Bump ch.qos.logback:logback-core from 1.2.9 to 1.2.14 in /.ci/jenkins/tests
Bump ch.qos.logback:logback-classic from 1.2.9 to 1.2.14 in /.ci/jenkins/tests

Consider unification, so that only one version is used across repository

This should replace existing PR's by depedabot, they upgrade to lower versions.
See #3318 #3317 and #3334 #3335

Implementation ideas

No response

@domhanak
Copy link
Contributor Author

domhanak commented Feb 6, 2024

@ricardozanini @fjtirado FYI

@fjtirado
Copy link
Contributor

fjtirado commented Feb 6, 2024

@domhanak Please go ahead merging the dependanbot ones

@ricardozanini
Copy link
Member

Can we close this?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: 📋 Backlog
Development

No branches or pull requests

3 participants