Skip to content

Comments

[Snyk] Upgrade: io.springfox:springfox-swagger-ui, io.springfox:springfox-swagger2, mysql:mysql-connector-java, net.lingala.zip4j:zip4j, org.projectlombok:lombok, org.springframework.boot:spring-boot-devtools, org.springframework.boot:spring-boot-starter, org.springframework.boot:spring-boot-starter-actuator, org.springframework.boot:spring-boot-starter-data-jpa, org.springframework.boot:spring-boot-starter-web, org.springframework.cloud:spring-cloud-starter-netflix-eureka-client, org.springframework.cloud:spring-cloud-starter-netflix-hystrix, org.springframework.cloud:spring-cloud-starter-openfeign, org.springframework.cloud:spring-cloud-starter-zipkin#526

Open
tt9133github wants to merge 1 commit intomasterfrom
snyk-upgrade-41f9663fc89dbe955b4627c3a369fe3a

Conversation

@tt9133github
Copy link
Owner

snyk-top-banner

Snyk has created this PR to upgrade multiple dependencies.

👯‍♂ The following dependencies are linked and will therefore be updated together.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.

Name Versions Released on

io.springfox:springfox-swagger-ui
from 2.6.1 to 2.10.5 | 10 versions ahead of your current version | 4 years ago
on 2020-06-23
io.springfox:springfox-swagger2
from 2.6.1 to 2.10.5 | 10 versions ahead of your current version | 4 years ago
on 2020-06-23
mysql:mysql-connector-java
from 5.1.43 to 5.1.49 | 6 versions ahead of your current version | 4 years ago
on 2020-04-20
net.lingala.zip4j:zip4j
from 1.3.2 to 1.3.3 | 1 version ahead of your current version | 5 years ago
on 2019-05-17
org.projectlombok:lombok
from 1.18.0 to 1.18.34 | 17 versions ahead of your current version | 2 months ago
on 2024-06-28
org.springframework.boot:spring-boot-devtools
from 2.0.6.RELEASE to 2.7.18 | 114 versions ahead of your current version | 10 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter
from 2.0.6.RELEASE to 2.7.18 | 114 versions ahead of your current version | 10 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter-actuator
from 2.0.6.RELEASE to 2.7.18 | 114 versions ahead of your current version | 10 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter-data-jpa
from 2.0.6.RELEASE to 2.7.18 | 114 versions ahead of your current version | 10 months ago
on 2023-11-23
org.springframework.boot:spring-boot-starter-web
from 2.0.6.RELEASE to 2.7.18 | 114 versions ahead of your current version | 10 months ago
on 2023-11-23
org.springframework.cloud:spring-cloud-starter-netflix-eureka-client
from 2.0.1.RELEASE to 2.2.10.RELEASE | 21 versions ahead of your current version | 3 years ago
on 2021-11-17
org.springframework.cloud:spring-cloud-starter-netflix-hystrix
from 2.0.1.RELEASE to 2.2.10.RELEASE | 21 versions ahead of your current version | 3 years ago
on 2021-11-17
org.springframework.cloud:spring-cloud-starter-openfeign
from 2.0.1.RELEASE to 2.2.10.RELEASE | 20 versions ahead of your current version | 3 years ago
on 2021-10-21
org.springframework.cloud:spring-cloud-starter-zipkin
from 2.0.1.RELEASE to 2.2.8.RELEASE | 20 versions ahead of your current version | 3 years ago
on 2021-04-21

Issues fixed by the recommended upgrade:

Issue Score Exploit Maturity
medium severity Arbitrary File Write via Archive Extraction (Zip Slip)
SNYK-JAVA-NETLINGALAZIP4J-31679
489 No Known Exploit

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade:
  - io.springfox:springfox-swagger-ui from 2.6.1 to 2.10.5.
    See this package in maven: https://mvnrepository.com/artifact/io.springfox/springfox-swagger-ui/
  - io.springfox:springfox-swagger2 from 2.6.1 to 2.10.5.
    See this package in maven: https://mvnrepository.com/artifact/io.springfox/springfox-swagger2/
  - mysql:mysql-connector-java from 5.1.43 to 5.1.49.
    See this package in maven: https://mvnrepository.com/artifact/mysql/mysql-connector-java/
  - net.lingala.zip4j:zip4j from 1.3.2 to 1.3.3.
    See this package in maven: https://mvnrepository.com/artifact/net.lingala.zip4j/zip4j/
  - org.projectlombok:lombok from 1.18.0 to 1.18.34.
    See this package in maven: https://mvnrepository.com/artifact/org.projectlombok/lombok/
  - org.springframework.boot:spring-boot-devtools from 2.0.6.RELEASE to 2.7.18.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-devtools/
  - org.springframework.boot:spring-boot-starter from 2.0.6.RELEASE to 2.7.18.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter/
  - org.springframework.boot:spring-boot-starter-actuator from 2.0.6.RELEASE to 2.7.18.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-actuator/
  - org.springframework.boot:spring-boot-starter-data-jpa from 2.0.6.RELEASE to 2.7.18.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-data-jpa/
  - org.springframework.boot:spring-boot-starter-web from 2.0.6.RELEASE to 2.7.18.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-web/
  - org.springframework.cloud:spring-cloud-starter-netflix-eureka-client from 2.0.1.RELEASE to 2.2.10.RELEASE.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.cloud/spring-cloud-starter-netflix-eureka-client/
  - org.springframework.cloud:spring-cloud-starter-netflix-hystrix from 2.0.1.RELEASE to 2.2.10.RELEASE.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.cloud/spring-cloud-starter-netflix-hystrix/
  - org.springframework.cloud:spring-cloud-starter-openfeign from 2.0.1.RELEASE to 2.2.10.RELEASE.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.cloud/spring-cloud-starter-openfeign/
  - org.springframework.cloud:spring-cloud-starter-zipkin from 2.0.1.RELEASE to 2.2.8.RELEASE.
    See this package in maven: https://mvnrepository.com/artifact/org.springframework.cloud/spring-cloud-starter-zipkin/

See this project in Snyk:
https://app.snyk.io/org/t438879/project/9e10e1aa-9230-4447-a18b-682be4a7844b?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants