Skip to content

Conversation

@bevzzz
Copy link
Collaborator

@bevzzz bevzzz commented Jul 14, 2025

‼️ org.apache.commons::commons-lang3 3.17.0 -> 3.18.0 prevents severe vulnerability: https://www.cve.org/CVERecord?id=CVE-2025-48924

Minor upgrades:

  • io.grpc:grpc-protobuf 1.70.0 -> 1.71.0
  • io.grpc:grpc-stub 1.68.2 -> 1.70.0
  • io.grpc:grpc-netty-shaded 1.68.2 -> 1.70.0
  • com.google.protobuf:protobuf-java(-util) 4.29.3 -> 4.30.0
  • and more: 4e18238, 2f08434

Supersedes these PRs: #359, #360, #365, #366, #367, #411, #412

gd org.apache.commons::commons-lang3 3.17.0 -> 3.18.0 prevents severe vulnerability:
https://www.cve.org/CVERecord?id=CVE-2025-48924

Minor upgrades:
- io.grpc:grpc-protobuf 1.70.0 -> 1.71.0
- io.grpc:grpc-stub 1.68.2 -> 1.70.0
- io.grpc:grpc-netty-shaded 1.68.2 -> 1.70.0
- com.google.protobuf:protobuf-java(-util) 4.29.3 -> 4.30.0
Copy link

@orca-security-eu orca-security-eu bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Orca Security Scan Summary

Status Check Issues by priority
Passed Passed Infrastructure as Code high 0   medium 0   low 0   info 0 View in Orca
Passed Passed SAST high 0   medium 0   low 0   info 0 View in Orca
Passed Passed Secrets high 0   medium 0   low 0   info 0 View in Orca
Passed Passed Vulnerabilities high 0   medium 0   low 0   info 0 View in Orca

@bevzzz bevzzz merged commit 30bc878 into main Jul 14, 2025
5 checks passed
@bevzzz bevzzz deleted the chore/upgrade-deps branch July 14, 2025 13:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants