terraform-maven
terraform-maven copied to clipboard
[Snyk] Security upgrade org.apache.maven.plugins:maven-dependency-plugin from 3.2.0 to 3.7.0
This PR was automatically created by Snyk using the credentials of a real user.

Snyk has created this PR to fix 4 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
tf-build-tools/tf-maven-plugin/pom.xml
Vulnerabilities that will be fixed with an upgrade:
| Issue | Score | Upgrade | |
|---|---|---|---|
| Infinite loop SNYK-JAVA-ORGAPACHECOMMONS-6254296 |
619 | org.apache.maven.plugins:maven-dependency-plugin: 3.2.0 -> 3.7.0 No Known Exploit |
|
| Information Disclosure SNYK-JAVA-COMGOOGLEGUAVA-1015415 |
486 | org.apache.maven.plugins:maven-dependency-plugin: 3.2.0 -> 3.7.0 Proof of Concept |
|
| Allocation of Resources Without Limits or Throttling SNYK-JAVA-ORGAPACHECOMMONS-6254297 |
429 | org.apache.maven.plugins:maven-dependency-plugin: 3.2.0 -> 3.7.0 No Known Exploit |
|
| Creation of Temporary File in Directory with Insecure Permissions SNYK-JAVA-COMGOOGLEGUAVA-5710356 |
379 | org.apache.maven.plugins:maven-dependency-plugin: 3.2.0 -> 3.7.0 No Known Exploit |
[!IMPORTANT]
- Check the changes in this PR to ensure they won't cause issues with your project.
- Max score is 1000. Note that the real score may have changed since the PR was raised.
- This PR was automatically created by Snyk using the credentials of a real user.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Creation of Temporary File in Directory with Insecure Permissions 🦉 Allocation of Resources Without Limits or Throttling