[ 
https://issues.apache.org/jira/browse/QPID-8331?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16951074#comment-16951074
 ] 

Mark Symons commented on QPID-8331:
-----------------------------------

It's great to know that the old version of Qpid is not vulnerable.  However, 
Analysis tools such as Dependency-Track do not know that and thus alert on the 
simple presence of the Derby version...  requiring extra work to triage and 
configure exceptions.

> [Broker-J] Upgrade derby dependency
> -----------------------------------
>
>                 Key: QPID-8331
>                 URL: https://issues.apache.org/jira/browse/QPID-8331
>             Project: Qpid
>          Issue Type: Improvement
>          Components: Broker-J
>            Reporter: Alex Rudyy
>            Assignee: Alex Rudyy
>            Priority: Major
>             Fix For: qpid-java-broker-8.0.0
>
>
> Upgrade derby dependency to version 10.14.2.0



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to