Skip to content

[fix][sec] Upgrade sqlite-jdbc to resolve CVE-2023-32697#20411

Merged
tisonkun merged 1 commit into
apache:masterfrom
lhotari:lh-update-sqlite-jdbc
May 26, 2023
Merged

[fix][sec] Upgrade sqlite-jdbc to resolve CVE-2023-32697#20411
tisonkun merged 1 commit into
apache:masterfrom
lhotari:lh-update-sqlite-jdbc

Conversation

@lhotari

@lhotari lhotari commented May 26, 2023

Copy link
Copy Markdown
Member

Motivation

Error:  Failed to execute goal org.owasp:dependency-check-maven:8.1.2:aggregate (default) on project pulsar: 
Error:  
Error:  One or more dependencies were identified with vulnerabilities that have a CVSS score greater than or equal to '7.0': 
Error:  
Error:  sqlite-jdbc-3.36.0.3.jar: CVE-2023-32697(8.8)

Modifications

Upgrade sqlite-jdbc

Documentation

  • doc
  • doc-required
  • doc-not-needed
  • doc-complete

@lhotari lhotari requested a review from nicoloboschi May 26, 2023 14:35
@lhotari lhotari self-assigned this May 26, 2023
@github-actions github-actions Bot added the doc-not-needed Your PR changes do not impact docs label May 26, 2023

@eolivelli eolivelli left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1

@nodece

nodece commented May 26, 2023

Copy link
Copy Markdown
Member

/pulsarbot rerun-failure-checks

@codecov-commenter

codecov-commenter commented May 26, 2023

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 72.86%. Comparing base (f0e97f4) to head (e5c526c).
⚠️ Report is 2125 commits behind head on master.

Additional details and impacted files

Impacted file tree graph

@@             Coverage Diff              @@
##             master   #20411      +/-   ##
============================================
+ Coverage     72.45%   72.86%   +0.41%     
+ Complexity    31898    31770     -128     
============================================
  Files          1852     1864      +12     
  Lines        138227   138416     +189     
  Branches      15175    15188      +13     
============================================
+ Hits         100150   100858     +708     
+ Misses        30098    29538     -560     
- Partials       7979     8020      +41     
Flag Coverage Δ
inttests 24.15% <ø> (-0.02%) ⬇️
systests 24.90% <ø> (?)
unittests 72.16% <ø> (-0.05%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.
see 159 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@tisonkun tisonkun merged commit a953027 into apache:master May 26, 2023
lhotari added a commit that referenced this pull request May 29, 2023
lhotari added a commit that referenced this pull request May 29, 2023
lhotari added a commit that referenced this pull request May 29, 2023
lhotari added a commit to datastax/pulsar that referenced this pull request May 29, 2023
(cherry picked from commit a953027)
(cherry picked from commit f2d7808)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants