Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix build for Linux for aarch64 #1891

Merged
merged 1 commit into from
Oct 10, 2023

Fix build for Linux for aarch64

f56cf8f
Select commit
Loading
Failed to load commit list.
Merged

Fix build for Linux for aarch64 #1891

Fix build for Linux for aarch64
f56cf8f
Select commit
Loading
Failed to load commit list.
This check has been archived and is scheduled for deletion. Learn more about checks retention
Mend for GitHub.com / WhiteSource Security Check succeeded Oct 10, 2023 in 2m 18s

Security Report

3 new vulnerabilities were introduced in this branch.

❌ New vulnerabilities:

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
CVE-2023-20883

Path to dependency file: /temporal-spring-boot-starter-alpha/build.gradle

Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.springframework.boot/spring-boot-autoconfigure/2.7.9/849b238dd024101cad8d107b4a8b0906f75003d5/spring-boot-autoconfigure-2.7.9.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.springframework.boot/spring-boot-autoconfigure/2.7.9/849b238dd024101cad8d107b4a8b0906f75003d5/spring-boot-autoconfigure-2.7.9.jar

Dependency Hierarchy:

-> ❌ spring-boot-autoconfigure-2.7.9.jar (Vulnerable Library)

High 7.5 spring-boot-autoconfigure-2.7.9.jar Upgrade to version: org.springframework.boot:spring-boot-autoconfigure:2.5.12,2.6.12,2.7.12,3.0.7 #1768
CVE-2023-20863

Path to dependency file: /temporal-spring-boot-starter-alpha/build.gradle

Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.springframework/spring-expression/5.3.25/d681cdb86611f03d8ef29654edde219fe5afef1d/spring-expression-5.3.25.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.springframework/spring-expression/5.3.25/d681cdb86611f03d8ef29654edde219fe5afef1d/spring-expression-5.3.25.jar

Dependency Hierarchy:

-> spring-boot-dependencies-2.7.9.pom (Root Library)

   -> ❌ spring-expression-5.3.25.jar (Vulnerable Library)

Medium 6.5 spring-expression-5.3.25.jar Upgrade to version: org.springframework:spring-expression - 5.2.24.RELEASE,5.3.27,6.0.8 #1738
CVE-2023-20861

Path to dependency file: /temporal-spring-boot-starter-alpha/build.gradle

Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.springframework/spring-expression/5.3.25/d681cdb86611f03d8ef29654edde219fe5afef1d/spring-expression-5.3.25.jar,/home/wss-scanner/.gradle/caches/modules-2/files-2.1/org.springframework/spring-expression/5.3.25/d681cdb86611f03d8ef29654edde219fe5afef1d/spring-expression-5.3.25.jar

Dependency Hierarchy:

-> spring-boot-dependencies-2.7.9.pom (Root Library)

   -> ❌ spring-expression-5.3.25.jar (Vulnerable Library)

Medium 6.5 spring-expression-5.3.25.jar Upgrade to version: org.springframework:spring-expression:x5.2.23.RELEASE,5.3.26,6.0.7 #1738

Base branch total remaining vulnerabilities: 15
Base branch commit: d5d96f84a4d251f4eccd0d15f8fe47e2ac96308d


Total libraries scanned: 171

Scan token: 7daeb0f27f4944c09baeb03d25167bd9