Skip to content

Update 'minio' version to resolve vulnerability in 'commons-compress' transitive dependency#2

Open
bigdaz wants to merge 1 commit intomainfrom
update-dependency-with-transitive-vulnerability
Open

Update 'minio' version to resolve vulnerability in 'commons-compress' transitive dependency#2
bigdaz wants to merge 1 commit intomainfrom
update-dependency-with-transitive-vulnerability

Conversation

@bigdaz
Copy link
Member

@bigdaz bigdaz commented Apr 4, 2024

Bump the version of io.minio:minio to 8.5.9, which in turn bumps the version of transitive dependnecy org.apache.commons:commons-compress to 1.26.0.

This resolves a Dependabot alert caused by a CVE in org.apache.common:commons-compress:1.24.0.

Bump the version of `io.minio:minio` to `8.5.9`, which in turn bumps the
version of transitive dependnecy `org.apache.commons:commons-compress` to `1.26.0`.

This resolves a Dependabot alert caused by a CVE in
`org.apache.common:commons-compress:1.24.0`.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant