-
Notifications
You must be signed in to change notification settings - Fork 293
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrading Guava to resolve CVE-2018-10237 #2073
Labels
comp: tooling
Build & Tooling
Comments
HI @smansouri, work is underway to remove our last runtime usage of guava in #2044 To ease some fear though, the classes mentioned in the CVE are not loaded by our agent. They are also hidden from standard class loaders so your application could not load them inadvertently. Guava classes loaded:
|
Merged
Merged
Thanks a lot, @devinsba for the update 🙏 |
Merged
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Hi,
We are using DataDog java agent in some of our projects, which are having a fixable security vulnerabiliy that can get resolved if Guava is upgraded to a version higher than 24.1.1. It seems that Guava version is set to 20.0 to support Java 7. Is there any plan to upgrade that?
The text was updated successfully, but these errors were encountered: