Skip to content

[MNG-7828] Bump guava from 30.1-jre to 32.0.1-jre#1191

Merged
gnodet merged 1 commit intoapache:masterfrom
bvolpato:bump-guava-master
Jul 11, 2023
Merged

[MNG-7828] Bump guava from 30.1-jre to 32.0.1-jre#1191
gnodet merged 1 commit intoapache:masterfrom
bvolpato:bump-guava-master

Conversation

@bvolpato
Copy link
Contributor

Update due to CVE-2023-2976.

See https://issues.apache.org/jira/browse/MNG-7828 for more context.

--

Doing on master too, following @cstamas instructions at #1189 (comment)

@bvolpato bvolpato changed the title Bump guava from 30.1-jre to 32.0.1-jre [MNG-7828] Bump guava from 30.1-jre to 32.0.1-jre Jun 28, 2023
@bvolpato
Copy link
Contributor Author

R: @cstamas

@ywluogg
Copy link

ywluogg commented Jun 29, 2023

I'm curious are there plans to bump this in 3.8.X?

@cstamas
Copy link
Member

cstamas commented Jun 29, 2023

Maven 3.8.x release will happen if someone comes up with some blocker bug, which i doubt. And I am curious, why not moving to 3.9.x line?

@ywluogg
Copy link

ywluogg commented Jul 4, 2023

I'm supporting some images built for Maven for some customers, and they still need 3.8.X, but we are requested to do a vulnerability patch for this.

@bvolpato
Copy link
Contributor Author

bvolpato commented Jul 5, 2023

I looked into it, but it's not very straightforward like the bump of <guavaVersion> here. In 3.8.x, Guava comes transitively from Guice.

@ywluogg
Copy link

ywluogg commented Jul 5, 2023

I looked into it, but it's not very straightforward like the bump of <guavaVersion> here. In 3.8.x, Guava comes transitively from Guice.

Thanks for this detail!

@ywluogg
Copy link

ywluogg commented Jul 5, 2023

Ah it seems like Guice has done the fix upstream: google/guice@331e484

@bvolpato
Copy link
Contributor Author

bvolpato commented Jul 6, 2023

Can a committer merge this PR? Thanks!

@gnodet gnodet merged commit bf56599 into apache:master Jul 11, 2023
@gnodet gnodet added this to the 4.0.0-alpha-8 milestone Jul 11, 2023
@bvolpato bvolpato deleted the bump-guava-master branch July 13, 2023 04:56
@ywluogg
Copy link

ywluogg commented Jul 24, 2023

Hi Maven team, I'm curious to see if Maven still considering doing patch for 3.8.X? We have customers that need to use 3.8.X since they have multiple repos with plugins that only work in 3.8.X.

@slachiewicz
Copy link
Member

not at this moment. Can You share more details (maybe links to bug reports to plugins repos?) about what issues Your projects have with Maven 3.9. This is active maintenance line of Maven.

@ywluogg
Copy link

ywluogg commented Jul 24, 2023

They are internal customers that I can't share their private customized plugins source code. Should we consider 3.8.X is in general out of scope for vulnerability patches?

@cstamas
Copy link
Member

cstamas commented Jul 24, 2023

Which Maven vulnerability you talk about specifically?

@ywluogg
Copy link

ywluogg commented Jul 24, 2023

Which Maven vulnerability you talk about specifically?

For requesting vulnerability patch in 3.8.X, I think I'm asking CVE-2023-2976.

But I wanted to know if 3.8.X is generally considered being excluded from vulnerability patches?

@cstamas
Copy link
Member

cstamas commented Jul 24, 2023

AFAIK Maven is not affected by CVE you refer to.

And no, 3.8.x is not excluded from reported vulnerability patches.

@cstamas
Copy link
Member

cstamas commented Jul 24, 2023

Please use ML https://maven.apache.org/mailing-lists.html for communication.

@apache apache locked as resolved and limited conversation to collaborators Jul 24, 2023
@jira-importer
Copy link

Resolve #9091

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants