zowe / data-sets

Repo for the springboot based data set APIs
Eclipse Public License 2.0
6 stars 5 forks source link

upgrade guava to 32.0.1-jre and snakeyaml to 2.0 #309

Closed AmandaDErrico closed 11 months ago

AmandaDErrico commented 11 months ago

Need to upgrade Guava to v32.0.1 as v32.0.0 breaks some functionality under Windows:

https://nvd.nist.gov/vuln/detail/CVE-2023-2976

Changing licenseGradlePluginVersion to 0.13.1 (same as jobs repo) also prevents errors when running job Publish branch binaries / publish (push).

sonarcloud[bot] commented 11 months ago

SonarCloud Quality Gate failed.    Quality Gate failed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 2 Code Smells

0.0% 0.0% Coverage
0.0% 0.0% Duplication

warning The version of Java (11.0.20) you have used to run this analysis is deprecated and we will stop accepting it soon. Please update to at least Java 17. Read more here

idea Catch issues before they fail your Quality Gate with our IDE extension sonarlint SonarLint