childprocess-vertx-ext
childprocess-vertx-ext copied to clipboard
Bump nuprocess from 1.2.4 to 2.0.5
Bumps nuprocess from 1.2.4 to 2.0.5.
Changelog
Sourced from nuprocess's changelog.
Changes in 2.0.5
- Fix command line injection vulnerability (CVE-2022-39243) (#143)
Changes in 2.0.4
- Add
Automatic-Module-Name
toMANIFEST.MF
to better support Java 9+ modules (#142)Changes in 2.0.3
- Add handling for
EINTR
duringepoll_wait
andESRCH
fromkill
to prevent zombie processes (#125, #131)- Remove static
EpollEvent
queue to avoid blocking under heavy load, which can lead to leaking zombie processes if a blocked thread is interrupted (#138)Changes in 2.0.2
- Ensure pipes are closed after failing to start a process on Linux, to prevent leaking descriptors (#120)
- Reduce pipe buffer size on Windows to increase process throughput to
stdout
andstderr
(#118)- Update JNA dependency to v5.8.0 to pick up support for the Apple M1 (#123)
Changes in 2.0.1
- Fix race condition between the
onStdinReady()
anduserWantsWrite()
methods that causes the state to become incorrect, resulting in failure to continue processing wantedstdin
writes (#113)Changes in 2.0.0
- Update JNA dependency to v5.5.0
- Add ability to run processes synchronously (#104)
- Handle detecting Java versions when non-numbers are present (#105)
Changes in 1.2.6
- Fix linkage issues with Azul JVMs. Special thanks to Bryan Turner for this pull request and extensive testing across a wide variety of JVMs. (#107)
Changes in 1.2.5
Changes in 1.2.4
Changes in 1.2.3
- Resolve launch issue on Linux/macOS w/Zulu JVM.
Changes in 1.2.2
... (truncated)
Commits
a2e0b17
[maven-release-plugin] prepare release nuprocess-2.0.529bc09d
Merge pull request #143 from benhumphreys/harden-null-injection467b28a
Null injection hardening (Adds tests)fabf505
Null injection hardening (Rework)d4005b6
Null injection hardening4953d61
[maven-release-plugin] prepare for next development iteration2b51da6
[maven-release-plugin] prepare release nuprocess-2.0.4f1d7250
Merge in 2.0.3 release changes.9b03f73
Merge pull request #142 from timboudreau/master9321b16
Fix whitespace nit.- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) -
@dependabot use these labels
will set the current labels as the default for future PRs for this repo and language -
@dependabot use these reviewers
will set the current reviewers as the default for future PRs for this repo and language -
@dependabot use these assignees
will set the current assignees as the default for future PRs for this repo and language -
@dependabot use this milestone
will set the current milestone as the default for future PRs for this repo and language
You can disable automated security fix PRs for this repo from the Security Alerts page.
Hi @vietj,
nuprocess:1.2.4
leads to this bug on MacOS when I try to compile vertx-starter. Upgrading to nuprocess:2.0.5
(or even 2.0.6
) fixes the issue. Tests in this project are still running fine. I'd love to see this PR merged.
Hi @vietj
nuprocess:1.2.4 have a vulnerability CVE-2022-39243. This vulnerability was fixed in 2.0.6 . So it will be nice to upgrade nuprocess version.
Cheer
Bonjour, Je vois que le problème existe pour d'autres personnes, pourrait-on avoir une nouvelle version de la librairie childprocess-vertx-ext avec la dépendance sur la version 2.0.6 de nuprocess. Merci d'avance