Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support for Apigee Edge version 1.3.4 dependency updates to reduce the number of vulnerabilities #235

Open
spjohn85 opened this issue Jun 16, 2024 · 7 comments

Comments

@spjohn85
Copy link

@ssvaidyanathan - We are using the 1.3.4 version of this deploy tool and when we download the dependencies, we are running into lot of violations for dependent pom files. Are there any plans to migrate them to latest versions to reduce the violations ?

I can help provide a report of violations from our customer environment if needed to private email address, but its quite a lot.

@ssvaidyanathan
Copy link
Collaborator

@spjohn85 - pls do send it to [email protected]

@spjohn85
Copy link
Author

@ssvaidyanathan - I did share this over email. Do you have any thoughts on how to resolve them ?

@ssvaidyanathan
Copy link
Collaborator

@spjohn85 - am still working on this. Been busy with a few other deliverables.
Feel free to submit a PR if you can update the pom dependencies and then am happy to merge that as well.

@ssvaidyanathan
Copy link
Collaborator

ssvaidyanathan commented Aug 16, 2024

@spjohn85 - can you pls confirm the sheet you sent with all the vulnerabilities is for the latest plugin? The versions you sent are not matching being used. Check this link for the pom dependencies. I want to be sure am working on the right codebase for fixing the versions

@spjohn85
Copy link
Author

@ssvaidyanathan - Yes, its this version. The report might have contained the poms of config-maven-plugin (1.5.5) as well since we are using both the tools.

@ssvaidyanathan
Copy link
Collaborator

@spjohn85 - if I update a branch in this repo, will you be able to run a report pointing to that and see if it made any difference?

@spjohn85
Copy link
Author

@ssvaidyanathan - If it can be downloaded from maven repository then I can get the report for new version. Its due to the process set currently, I cannot manually run them.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants