KNOX-3121 - Update spring-expressions for CVE-2024-38808#1017
KNOX-3121 - Update spring-expressions for CVE-2024-38808#1017Preetesh2110 wants to merge 1 commit intoapache:masterfrom
Conversation
|
@moresandeep could you please review this PR. |
moresandeep
left a comment
There was a problem hiding this comment.
Thanks @Preetesh2110, i kicked off the checks, we can merge the changes when the checks pass.
|
Hey I ran the build and tests locally with Java 11 and everything seems to be passing. Also the failures seems unrelated Can we please rerun the workflow. |
Weird, sure i can kickstart it again. |
|
@moresandeep really sorry to bug you so many times. This time the previous failure disappeared and a new failure occurred at |
|
Could we please re-trigger the workflow. |
|
@Preetesh2110 that's okay, something weird is going on. I'll keep na eye on it. |
|
@Preetesh2110 the failure is because of the following issue: Looks like an issue with pulling dependencies unrelated to your patch. |
|
Thanks a lot Sandeep! |
|
Cleared caches and triggered new builds. |
|
Thanks @smolnar82 updated the description. |
|
I think there is an actual issue with the new version of Spring, which should be handled (exclude/upgrade, etc...). I'm glad we have the dependency enforcer tool as part of our builds. |
|
I'm going to close this PR in 5 days in case there is no activity on it. |
What changes were proposed in this pull request?
Update spring-expressions for CVE-2024-38808
How was this patch tested?
Here is the output