sdk-java icon indicating copy to clipboard operation
sdk-java copied to clipboard

Bump jsonpath to 2.9.0 to fix the vulnerability

Open vishnu1074 opened this issue 1 year ago • 1 comments

Describe what has changed in this PR

Currently temporal-testing is using json path 2.8.0 which is causing the temporal-testing to have a CVE detected in maven.

Temporal-testing mvn: https://mvnrepository.com/artifact/io.temporal/temporal-testing/1.23.2

jsonpath mvn: https://mvnrepository.com/artifact/com.jayway.jsonpath/json-path

To fix this, I am bumping the jsonpath version to 2.9.0 which seems to be free from the cve.

Why I made this change ?

I want to use temporal for my projects and snyk is detecting a vulnerability for temporal-testing jar(3p vulnerability). Hence fixing this.

vishnu1074 avatar Jun 19 '24 08:06 vishnu1074