Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Unresolved CVE on JGit 5.x. Possible to move to JGit 6.x? #177

Closed
chrned opened this issue Jan 26, 2024 · 3 comments
Closed

Unresolved CVE on JGit 5.x. Possible to move to JGit 6.x? #177

chrned opened this issue Jan 26, 2024 · 3 comments

Comments

@chrned
Copy link

chrned commented Jan 26, 2024

Hi.

This project currently depends on JGit 5.13.1.202206130422-r which is associated with CVE-2023-4759.

This prevents projects that perform vulnerability scanning from building with a dependency to git-changelog-lib.

The CVE is resolved in JGit releases newer than 6.6.0.202305301015-r.

Regards
Christian

tomasbjerre added a commit that referenced this issue Jan 26, 2024
BREAKING CHANGE: JGit major version from 5 to 6 and require Java 11 (refs #177)
tomasbjerre added a commit that referenced this issue Jan 26, 2024
BREAKING CHANGE: JGit major version from 5 to 6 and require Java 11 (refs #177)
tomasbjerre added a commit that referenced this issue Jan 26, 2024
BREAKING CHANGE: JGit major version from 5 to 6 and require Java 11 (refs #177)
@tomasbjerre
Copy link
Owner

It would mean dropping Java 8 support but I think it is time for that anyway.

tomasbjerre added a commit that referenced this issue Jan 27, 2024
BREAKING CHANGE: JGit major version from 5 to 6 and require Java 11 (refs #177)
@tomasbjerre
Copy link
Owner

This is released now, open issue again if any problems.

@chrned
Copy link
Author

chrned commented Jan 29, 2024

Thanks for the quick turnaround on this :)

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants