[Snyk] Fix for 3 vulnerabilities - #53
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-IONETTY-18170202 - https://snyk.io/vuln/SNYK-JAVA-IONETTY-18170204 - https://snyk.io/vuln/SNYK-JAVA-IONETTY-18170213
|
This update contains a high-risk major version upgrade for Quarkus and a low-risk minor version upgrade for the AWS SDK. High Risk: io.quarkus:quarkus-smallrye-health@1.4.1.Final → 2.3.0.FinalThis is a major platform upgrade from Quarkus 1.x to 2.x, which introduces significant breaking changes and requires developer action. It is not specific to the Key Breaking Changes:
Recommendation: A dedicated migration effort is required. Developers must consult the Quarkus 2.0 Migration Guide to address the necessary changes. This upgrade should not be merged without thorough testing and potential code modifications. Low Risk: software.amazon.awssdk:kinesis@2.13.13 → 2.48.4This is a minor version upgrade within the AWS SDK for Java v2. The SDK maintains a strong backward compatibility promise for minor version updates. The changes between these versions consist primarily of new features, performance improvements, and bug fixes. No breaking API changes are documented for the Kinesis client in this version range. Source: AWS SDK for Java v2 Changelog
|
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
Snyk has created this PR to fix 3 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
debezium-server/pom.xmlVulnerabilities that will be fixed with an upgrade:
SNYK-JAVA-IONETTY-18170202
2.13.13->2.48.4Major version upgradeNo Path FoundProof of ConceptSNYK-JAVA-IONETTY-18170204
2.13.13->2.48.4Major version upgradeNo Path FoundProof of ConceptSNYK-JAVA-IONETTY-18170213
2.13.13->2.48.4Major version upgradeNo Path FoundNo Known ExploitBreaking Change Risk
Vulnerabilities that could not be fixed
io.quarkus:quarkus-smallrye-health@1.4.1.Finaltoio.quarkus:quarkus-smallrye-health@2.3.0.Final; Reasoncould not apply upgrade, dependency is managed externally; Location:provenance does not contain locationImportant
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling