This is an automated email from the ASF dual-hosted git repository.

pefernan pushed a commit to branch main
in repository 
https://gitbox.apache.org/repos/asf/incubator-kie-kogito-runtimes.git


The following commit(s) were added to refs/heads/main by this push:
     new 965c335fac NO_ISSUE: Overriding commons-compress version to fix 
CVE-2023-42503 present in 1.22 (#3269)
965c335fac is described below

commit 965c335fac825f35473e0536e35fe52fa79db063
Author: Pere Fernández <[email protected]>
AuthorDate: Tue Oct 31 17:58:35 2023 +0100

    NO_ISSUE: Overriding commons-compress version to fix CVE-2023-42503 present 
in 1.22 (#3269)
---
 kogito-build/kogito-dependencies-bom/pom.xml | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/kogito-build/kogito-dependencies-bom/pom.xml 
b/kogito-build/kogito-dependencies-bom/pom.xml
index 704ab81459..21a11e42a5 100644
--- a/kogito-build/kogito-dependencies-bom/pom.xml
+++ b/kogito-build/kogito-dependencies-bom/pom.xml
@@ -126,6 +126,7 @@
     <version.com.github.stephenc.jcip>1.0-1</version.com.github.stephenc.jcip>
     <version.black.ninia>4.1.1</version.black.ninia>
     <version.com.google.guava>32.0.1-jre</version.com.google.guava>
+    
<version.apache.commons.commons-compress>1.24.0</version.apache.commons.commons-compress>
   </properties>
 
   <dependencyManagement>
@@ -136,6 +137,13 @@
         <artifactId>guava</artifactId>
         <version>${version.com.google.guava}</version>
       </dependency>
+
+      <dependency>
+        <groupId>org.apache.commons</groupId>
+        <artifactId>commons-compress</artifactId>
+        <version>${version.apache.commons.commons-compress}</version>
+      </dependency>
+
       <dependency>
         <groupId>org.slf4j</groupId>
         <artifactId>slf4j-api</artifactId>


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to