Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: bump protobuff due to CVE 2021 22569 #102

Merged
merged 2 commits into from
Jul 27, 2022

Conversation

kuisathaverat
Copy link
Contributor

@car-roll
Copy link

car-roll commented Jul 26, 2022

@kuisathaverat what is the plan for this PR? Is dependabot going to handle the downstream merge of this in lieu of jenkinsci/trilead-api-plugin#59? I believe there were some issues with incrementals in trilead-api? many thanks!

@kuisathaverat
Copy link
Contributor Author

yep, the idea is to merge and release it, then wait for dependabot update trilead-api and then release trilead-api, it has to happen in a window of time I can monitor issues related to being able to fix them. I do not expect any issue but, better be cautious, this version of trilead-ssh2 is not compatible with JDK 8, so I will bump the Jenkins core version to grap one that warning about to use JDK 11

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants