[MCHANGES-455] Freshly released plugin contains CVE-warnings

Open
#384 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
25/100
Issue type
Bug
Clarity
Needs clarification
Activity status
Stale
Tech stack
java

Research direction

Start by inspecting the dependency warnings reported for maven-changes-plugin 3.0.0-M1 on the linked Maven Repository page and compare them with the plugin's release dependency tree. Identify the two CVEs and confirm that a dependency update or exclusion removes them in a subsequent release.

Written by the indexing model from the issue text.

Description

dependencies priority:major

Philipp Ottlinger opened MCHANGES-455 and commented

I was happy to find the new RC 3.0.0-M1 ... when I had a look at

 

https://mvnrepository.com/artifact/org.apache.maven.plugins/maven-changes-plugin/3.0.0-M1

I already saw 2 CVE-warnings. Not sure how easy these can be fixed in the next release cycle.

 

Thanks for all your work and help


Affects: 3.0.0-M1

Issue Links:

Dominant language
Java
Stars
15
Forks
22
Avg merge
1d 6h
Merged PRs (30d)
7

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/maven-changes-plugin

All issues in apache/maven-changes-plugin

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.