Thank you for opening a pull request and contributing to AsciidoctorJ!
Please take a bit of time giving some details about your pull request:
Kind of change
[ ] Bug fix
[ ] New non-breaking feature
[ ] New breaking feature
[ ] Documentation update
[x] Build improvement
Description
What is the goal of this pull request?
Sonatype sent a warning that we are still relying on unit 4.12 which has an open CVE.
Indeed asciidoctorj-test-support still has that dependency even though the build itself should already have used the fixed version 4.13.2.
This PR upgrades this last remaining dependency to 4.13.2 too to avoid that CVE.
How does it achieve that?
Are there any alternative ways to implement this?
Are there any implications of this pull request? Anything a user must know?
Issue
If this PR fixes an open issue, please add a line of the form:
Fixes #Issue
Release notes
Please add a corresponding entry to the file CHANGELOG.adoc
Thank you for opening a pull request and contributing to AsciidoctorJ!
Please take a bit of time giving some details about your pull request:
Kind of change
Description
What is the goal of this pull request?
Sonatype sent a warning that we are still relying on unit 4.12 which has an open CVE. Indeed asciidoctorj-test-support still has that dependency even though the build itself should already have used the fixed version 4.13.2. This PR upgrades this last remaining dependency to 4.13.2 too to avoid that CVE.
How does it achieve that?
Are there any alternative ways to implement this?
Are there any implications of this pull request? Anything a user must know?
Issue
If this PR fixes an open issue, please add a line of the form:
Fixes #Issue
Release notes
Please add a corresponding entry to the file CHANGELOG.adoc