-
Notifications
You must be signed in to change notification settings - Fork 617
fix(deps): update dependency org.codehaus.groovy:groovy-all to v2.4.21 [security] #5153
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix(deps): update dependency org.codehaus.groovy:groovy-all to v2.4.21 [security] #5153
Conversation
70e7c12 to
99f7f22
Compare
5e6adb7 to
2c50a0f
Compare
482b254 to
c32fb08
Compare
e58ded9 to
843824f
Compare
9437124 to
51089f6
Compare
|
/it-go |
7a07e81 to
2369698
Compare
|
/it-go |
2369698 to
c7354a7
Compare
|
/it-go |
c7354a7 to
dcca2d5
Compare
|
/it-go |
dcca2d5 to
e832d09
Compare
|
/it-go |
e832d09 to
c613433
Compare
|
/it-go |
c613433 to
ff5e152
Compare
|
/it-go |
ff5e152 to
eb2d42d
Compare
|
/it-go |
eb2d42d to
710480e
Compare
|
/it-go |
710480e to
12a87dc
Compare
|
/it-go |
12a87dc to
0a25084
Compare
|
/it-go |
|
|
Thank you for your contribution! This pull request is stale because it has been open 60 days with no activity. In order to keep it open, please remove stale label or add a comment within the next 10 days. If you need a Piper team member to remove the stale label make sure to add |
|
Pull request got stale and no further activity happened. It has automatically been closed. Please re-open in case you still consider it relevant. |
Renovate Ignore NotificationBecause you closed this PR without merging, Renovate will ignore this update ( If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR. |



This PR contains the following updates:
2.4.12->2.4.21Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
GitHub Vulnerability Alerts
CVE-2020-17521
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected, but may wish to read the advisory for further details. Versions Affected: 2.0 to 2.4.20, 2.5.0 to 2.5.13, 3.0.0 to 3.0.6, and 4.0.0-alpha-1. Fixed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0-alpha-2.
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.