Closed snyk-bot closed 3 years ago
@jamsden this is why I do not want to support the old client. If someone wants it, they stick to 2.4.0.
I fixed the new client https://github.com/eclipse/lyo.client/pull/63 but I don't have resources to check Jena upgrades don't break the old client. And I am refusing to release client with vulnerable dependencies.
I suggest simply to remove the old client from the repo and tell people to use v2.4.0 if they can't upgrade.
cc @jadelkhoury
Superseded by an upgrade to Jena 3.14
Description
This PR fixes one or more vulnerable packages in the
maven
dependencies of this project. See the Snyk test report for more details.Snyk Project: eclipse/lyo.client:oslc-java-client/pom.xml
Snyk Organization: berezovskyi
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
oslc-java-client/pom.xml
org.apache.jena:apache-jena-libs@3.6.0 > org.apache.jena:apache-jena-libs@3.11.0
You can read more about Snyk's upgrade and patch logic in Snyk's documentation.
Check the changes in this PR to ensure they won't cause issues with your project.
Stay secure, The Snyk team
Note: You are seeing this because you or someone else with access to this repository has authorised Snyk to open Fix PRs. To review the settings for this Snyk project please go to the project settings page.