aurora icon indicating copy to clipboard operation
aurora copied to clipboard

Upgrading dependencies to mitigate vulnerabilities

Open ridv opened this issue 6 years ago • 0 comments

Description:

A bot recently reported a large number of vulnerabilities that we inherited from our dependencies.

Creating a draft PR while I verify that these dependency upgrades do not have a negative impact.

Components upgraded:

  • Curator
  • Zookeeper
  • Shiro
  • Netty
  • Asynchttpclient
  • Quartz
  • Gradle
  • Gradle plugins
  • Jackson
  • Guice
  • Guava
  • Multiple react components.

Testing Done:

TODO

We should run a few end to end test runs to confirm everything is good.

After we merge this PR we need to create a PR for packaging which upgrades the gradle version there.

ridv avatar Oct 03 '19 01:10 ridv