-
Notifications
You must be signed in to change notification settings - Fork 5.5k
Upgrade the jar org.apache.commons:commons-text:1.10.0 to 1.13.0 #24467
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
|
492b7a2 to
f26d4d7
Compare
dc51f16 to
18045ac
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Please update commit message somethng like -
Upgrade commons-text dependency to address <CVE-Link>
18045ac to
cc76355
Compare
|
New release note guidelines as of last week: PR #24354 automatically adds links to this PR to the release notes. Please remove the manual PR link in the following format from the release note entries for this PR. I have updated the Release Notes Guidelines to remove the examples of manually adding the PR link. |
Addressed the comment |
|
@sumi-mathew The Current commit message is long doesn't follow commit guidelines - https://github.com/prestodb/presto/blob/master/CONTRIBUTING.md#commit-message-style |
cc76355 to
50d8890
Compare
50d8890 to
c0c259e
Compare
Description
Upgrade the org.apache.commons:commons-text dependency from version 1.10.0 to 1.13.0 to avoiding CVE issues.
As part of this , upgraded commons.lang3 - 3.14.0 to 3.17.0
Motivation and Context
Upgrading the org.apache.commons:commons-text dependency from version 1.10.0 to 1.13.0 to reduce the risk of introducing new security flaws
Impact
Test Plan
Contributor checklist
Release Notes
Please follow release notes guidelines and fill in the release notes below.