[ https://issues.apache.org/jira/browse/JENA-2222?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17462164#comment-17462164 ]
ASF subversion and git services commented on JENA-2222: ------------------------------------------------------- Commit 9c5859efb1a4cdbbcbd1d6cb819108e710a91494 in jena's branch refs/heads/main from Andy Seaborne [ https://gitbox.apache.org/repos/asf?p=jena.git;h=9c5859ef ] JENA-2222: Move version mgt into Jena root POM. > Dependency updates for jena-geosparql and jena-fuseki-geosparql > --------------------------------------------------------------- > > Key: JENA-2222 > URL: https://issues.apache.org/jira/browse/JENA-2222 > Project: Apache Jena > Issue Type: Task > Components: GeoSPARQL > Affects Versions: Jena 4.3.2 > Reporter: Andy Seaborne > Assignee: Andy Seaborne > Priority: Critical > Fix For: Jena 4.4.0 > > > Found by running > {{mvn org.sonatype.ossindex.maven:ossindex-maven-plugin:audit -fn -f pom.xml}} > {{jdom:jdom2}} and {{commons-beanutils:commons-beanutils}} are dependencies > and need updates. > jdom:jdom2 : CVE-2021-33813 : 2.0.6 -> 2.0.6.1 > beanutils: CVE-2019-10086 :1.9.3->1.9.4 > Also: > Ideally, the version of all dependencies should be controlled in the Jena top > POM. -- This message was sent by Atlassian Jira (v8.20.1#820001)