[Snyk] Upgrade: com.alibaba:fastjson, commons-fileupload:commons-fileupload, io.github.openfeign.form:feign-form, io.github.openfeign.form:feign-form-spring, io.springfox:springfox-swagger-ui, io.springfox:springfox-swagger2, mysql:mysql-connector-java, org.apache.logging.log4j:log4j-core, org.apache.velocity:velocity, org.projectlombok:lombok, org.springframework.boot:spring-boot-devtools, org.springframework.boot:spring-boot-starter, org.springframework.boot:spring-boot-starter-actuator, org.springframework.boot:spring-boot-starter-data-jpa, org.springframework.boot:spring-boot-starter-data-mongodb, org.springframework.boot:spring-boot-starter-data-redis, org.springframework.boot:spring-boot-starter-web, org.springframework.cloud:spring-cloud-starter-netflix-eureka-client, org.springframework.cloud:spring-cloud-starter-netflix-hystrix, org.springframework.cloud:spring-cloud-starter-openfeign, org.springframework.cloud:spring-cloud-starter-zipkin#525
Open
tt9133github wants to merge 1 commit intomasterfrom
Open
[Snyk] Upgrade: com.alibaba:fastjson, commons-fileupload:commons-fileupload, io.github.openfeign.form:feign-form, io.github.openfeign.form:feign-form-spring, io.springfox:springfox-swagger-ui, io.springfox:springfox-swagger2, mysql:mysql-connector-java, org.apache.logging.log4j:log4j-core, org.apache.velocity:velocity, org.projectlombok:lombok, org.springframework.boot:spring-boot-devtools, org.springframework.boot:spring-boot-starter, org.springframework.boot:spring-boot-starter-actuator, org.springframework.boot:spring-boot-starter-data-jpa, org.springframework.boot:spring-boot-starter-data-mongodb, org.springframework.boot:spring-boot-starter-data-redis, org.springframework.boot:spring-boot-starter-web, org.springframework.cloud:spring-cloud-starter-netflix-eureka-client, org.springframework.cloud:spring-cloud-starter-netflix-hystrix, org.springframework.cloud:spring-cloud-starter-openfeign, org.springframework.cloud:spring-cloud-starter-zipkin#525tt9133github wants to merge 1 commit intomasterfrom
tt9133github wants to merge 1 commit intomasterfrom
Conversation
Snyk has created this PR to upgrade:
- com.alibaba:fastjson from 1.2.12 to 1.2.83_noneautotype.
See this package in maven: https://mvnrepository.com/artifact/com.alibaba/fastjson/
- commons-fileupload:commons-fileupload from 1.3.3 to 1.5.
See this package in maven: https://mvnrepository.com/artifact/commons-fileupload/commons-fileupload/
- io.github.openfeign.form:feign-form from 3.0.3 to 3.8.0.
See this package in maven: https://mvnrepository.com/artifact/io.github.openfeign.form/feign-form/
- io.github.openfeign.form:feign-form-spring from 3.0.3 to 3.8.0.
See this package in maven: https://mvnrepository.com/artifact/io.github.openfeign.form/feign-form-spring/
- io.springfox:springfox-swagger-ui from 2.6.1 to 2.10.5.
See this package in maven: https://mvnrepository.com/artifact/io.springfox/springfox-swagger-ui/
- io.springfox:springfox-swagger2 from 2.6.1 to 2.10.5.
See this package in maven: https://mvnrepository.com/artifact/io.springfox/springfox-swagger2/
- mysql:mysql-connector-java from 5.1.17 to 5.1.49.
See this package in maven: https://mvnrepository.com/artifact/mysql/mysql-connector-java/
- org.apache.logging.log4j:log4j-core from 2.10.0 to 2.23.1.
See this package in maven: https://mvnrepository.com/artifact/org.apache.logging.log4j/log4j-core/
- org.apache.velocity:velocity from 1.6.4 to 1.7.
See this package in maven: https://mvnrepository.com/artifact/org.apache.velocity/velocity/
- org.projectlombok:lombok from 1.18.0 to 1.18.34.
See this package in maven: https://mvnrepository.com/artifact/org.projectlombok/lombok/
- org.springframework.boot:spring-boot-devtools from 2.0.6.RELEASE to 2.7.18.
See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-devtools/
- org.springframework.boot:spring-boot-starter from 2.0.6.RELEASE to 2.7.18.
See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter/
- org.springframework.boot:spring-boot-starter-actuator from 2.0.6.RELEASE to 2.7.18.
See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-actuator/
- org.springframework.boot:spring-boot-starter-data-jpa from 2.0.6.RELEASE to 2.7.18.
See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-data-jpa/
- org.springframework.boot:spring-boot-starter-data-mongodb from 2.0.6.RELEASE to 2.7.18.
See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-data-mongodb/
- org.springframework.boot:spring-boot-starter-data-redis from 2.0.6.RELEASE to 2.7.18.
See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-data-redis/
- org.springframework.boot:spring-boot-starter-web from 2.0.6.RELEASE to 2.7.18.
See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-web/
- org.springframework.cloud:spring-cloud-starter-netflix-eureka-client from 2.0.1.RELEASE to 2.2.10.RELEASE.
See this package in maven: https://mvnrepository.com/artifact/org.springframework.cloud/spring-cloud-starter-netflix-eureka-client/
- org.springframework.cloud:spring-cloud-starter-netflix-hystrix from 2.0.1.RELEASE to 2.2.10.RELEASE.
See this package in maven: https://mvnrepository.com/artifact/org.springframework.cloud/spring-cloud-starter-netflix-hystrix/
- org.springframework.cloud:spring-cloud-starter-openfeign from 2.0.1.RELEASE to 2.2.10.RELEASE.
See this package in maven: https://mvnrepository.com/artifact/org.springframework.cloud/spring-cloud-starter-openfeign/
- org.springframework.cloud:spring-cloud-starter-zipkin from 2.0.1.RELEASE to 2.2.8.RELEASE.
See this package in maven: https://mvnrepository.com/artifact/org.springframework.cloud/spring-cloud-starter-zipkin/
See this project in Snyk:
https://app.snyk.io/org/t438879/project/8251b969-d2c4-48a6-935c-c0914417c8c0?utm_source=github&utm_medium=referral&page=upgrade-pr
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Snyk has created this PR to upgrade multiple dependencies.
👯 The following dependencies are linked and will therefore be updated together.ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
com.alibaba:fastjson
from 1.2.12 to 1.2.83_noneautotype | 124 versions ahead of your current version | 2 years ago
on 2022-06-13
commons-fileupload:commons-fileupload
from 1.3.3 to 1.5 | 2 versions ahead of your current version | 2 years ago
on 2023-02-01
io.github.openfeign.form:feign-form
from 3.0.3 to 3.8.0 | 8 versions ahead of your current version | 5 years ago
on 2019-03-29
io.github.openfeign.form:feign-form-spring
from 3.0.3 to 3.8.0 | 8 versions ahead of your current version | 5 years ago
on 2019-03-29
io.springfox:springfox-swagger-ui
from 2.6.1 to 2.10.5 | 10 versions ahead of your current version | 4 years ago
on 2020-06-23
io.springfox:springfox-swagger2
from 2.6.1 to 2.10.5 | 10 versions ahead of your current version | 4 years ago
on 2020-06-23
mysql:mysql-connector-java
from 5.1.17 to 5.1.49 | 32 versions ahead of your current version | 4 years ago
on 2020-04-20
org.apache.logging.log4j:log4j-core
from 2.10.0 to 2.23.1 | 28 versions ahead of your current version | 6 months ago
on 2024-03-06
org.apache.velocity:velocity
from 1.6.4 to 1.7 | 2 versions ahead of your current version | 14 years ago
on 2010-11-29
org.projectlombok:lombok
from 1.18.0 to 1.18.34 | 17 versions ahead of your current version | 2 months ago
on 2024-06-28
org.springframework.boot:spring-boot-devtools
from 2.0.6.RELEASE to 2.7.18 | 114 versions ahead of your current version | 9 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter
from 2.0.6.RELEASE to 2.7.18 | 114 versions ahead of your current version | 9 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter-actuator
from 2.0.6.RELEASE to 2.7.18 | 114 versions ahead of your current version | 9 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter-data-jpa
from 2.0.6.RELEASE to 2.7.18 | 114 versions ahead of your current version | 9 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter-data-mongodb
from 2.0.6.RELEASE to 2.7.18 | 114 versions ahead of your current version | 9 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter-data-redis
from 2.0.6.RELEASE to 2.7.18 | 114 versions ahead of your current version | 9 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter-web
from 2.0.6.RELEASE to 2.7.18 | 114 versions ahead of your current version | 9 months ago
on 2023-11-23
org.springframework.cloud:spring-cloud-starter-netflix-eureka-client
from 2.0.1.RELEASE to 2.2.10.RELEASE | 21 versions ahead of your current version | 3 years ago
on 2021-11-17
org.springframework.cloud:spring-cloud-starter-netflix-hystrix
from 2.0.1.RELEASE to 2.2.10.RELEASE | 21 versions ahead of your current version | 3 years ago
on 2021-11-17
org.springframework.cloud:spring-cloud-starter-openfeign
from 2.0.1.RELEASE to 2.2.10.RELEASE | 20 versions ahead of your current version | 3 years ago
on 2021-10-21
org.springframework.cloud:spring-cloud-starter-zipkin
from 2.0.1.RELEASE to 2.2.8.RELEASE | 20 versions ahead of your current version | 3 years ago
on 2021-04-21
Issues fixed by the recommended upgrade:
SNYK-JAVA-COMALIBABA-2859222
SNYK-JAVA-COMALIBABA-570967
SNYK-JAVA-COMMONSFILEUPLOAD-3326457
SNYK-JAVA-COMMONSIO-1277109
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2314720
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2320014
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2321524
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-2327339
SNYK-JAVA-COMALIBABA-73578
SNYK-JAVA-ORGAPACHELOGGINGLOG4J-567761
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
For more information: