Closed snyk-bot closed 4 years ago
Merging #133 into master will not change coverage. The diff coverage is
n/a
.
@@ Coverage Diff @@
## master #133 +/- ##
=========================================
Coverage 84.67% 84.67%
Complexity 120 120
=========================================
Files 23 23
Lines 607 607
Branches 77 77
=========================================
Hits 514 514
Misses 69 69
Partials 24 24
Continue to review full report at Codecov.
Legend - Click here to learn more
Ξ = absolute <relative> (impact)
,ΓΈ = not affected
,? = missing data
Powered by Codecov. Last update 857685a...dc18281. Read the comment docs.
Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
cas-security-spring-boot-sample/pom.xml
com.fasterxml.jackson.core:jackson-databind@2.9.9.3 > com.fasterxml.jackson.core:jackson-databind@2.10.0
Vulnerabilities that could not be fixed
org.springframework.boot:spring-boot-starter-actuator@2.1.7.RELEASE
toorg.springframework.boot:spring-boot-starter-actuator@2.2.0.RELEASE
; Reasoncould not apply upgrade, dependency is managed externally
; Location:https://maven-central.storage-download.googleapis.com/repos/central/data/org/springframework/boot/spring-boot-dependencies/2.1.7.RELEASE/spring-boot-dependencies-2.1.7.RELEASE.pom
org.springframework.boot:spring-boot-starter-web@2.1.7.RELEASE
toorg.springframework.boot:spring-boot-starter-web@2.2.0.RELEASE
; Reasoncould not apply upgrade, dependency is managed externally
; Location:https://maven-central.storage-download.googleapis.com/repos/central/data/org/springframework/boot/spring-boot-dependencies/2.1.7.RELEASE/spring-boot-dependencies-2.1.7.RELEASE.pom
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
π§ View latest project report
π Adjust project settings
π Read more about Snyk's upgrade and patch logic