Skip to content
Snippets Groups Projects
bhill6@wisc.edu's avatar
deleted branch update_deployment_job at adi-ia / uw-spring-security
bhill6@wisc.edu's avatar
accepted merge request !37 "Updated branch restriction on deploy job from trunk to main" at adi-ia / uw-spring-security
bhill6@wisc.edu's avatar
pushed to branch main at adi-ia / uw-spring-security
Lyle Hanson's avatar
approved merge request !37 "Updated branch restriction on deploy job from trunk to main" at adi-ia / uw-spring-security
bhill6@wisc.edu's avatar
opened merge request !37 "Updated branch restriction on deploy job from trunk to main" at adi-ia / uw-spring-security
bhill6@wisc.edu's avatar
pushed to branch update_deployment_job at adi-ia / uw-spring-security
bhill6@wisc.edu's avatar
pushed new branch update_deployment_job at adi-ia / uw-spring-security
bhill6@wisc.edu's avatar
deleted branch dependency_updates at adi-ia / uw-spring-security
bhill6@wisc.edu's avatar
pushed to branch main at adi-ia / uw-spring-security
bhill6@wisc.edu's avatar
accepted merge request !36 "Dependency updates to eliminate vulnerabilities discovered by dependency-check" at adi-ia / uw-spring-security
bhill6@wisc.edu's avatar
approved merge request !36 "Dependency updates to eliminate vulnerabilities discovered by dependency-check" at adi-ia / uw-spring-security
bhill6@wisc.edu's avatar
commented on merge request !36 "Dependency updates to eliminate vulnerabilities discovered by dependency-check" at adi-ia / uw-spring-security

Regarding the Jackson vulnerabilities. What's odd is that it states that we need to update to 2.14.0-rc1 or higher, but we did and are still gettin...

Lyle Hanson's avatar
approved merge request !36 "Dependency updates to eliminate vulnerabilities discovered by dependency-check" at adi-ia / uw-spring-security
bhill6@wisc.edu's avatar
pushed to branch dependency_updates at adi-ia / uw-spring-security
  • d30c4244 · Updating 'revision' property in pom file that's used by UWFrame bui...
bhill6@wisc.edu's avatar
pushed to branch dependency_updates at adi-ia / uw-spring-security
Lyle Hanson's avatar
commented on merge request !36 "Dependency updates to eliminate vulnerabilities discovered by dependency-check" at adi-ia / uw-spring-security

Silence Maven warning "[WARNING] File encoding has not been set, using platform encoding UTF-8, i.e. build is platform dependent!"...

bhill6@wisc.edu's avatar
pushed to branch dependency_updates at adi-ia / uw-spring-security
  • 0b83cff8 · removed unused cvs-suppressions file
bhill6@wisc.edu's avatar
pushed to branch dependency_updates at adi-ia / uw-spring-security
Lyle Hanson's avatar
commented on merge request !36 "Dependency updates to eliminate vulnerabilities discovered by dependency-check" at adi-ia / uw-spring-security

Since we're no longer using the dependency-check maven plugin, this file can probably be deleted and suppressions can be handled in GitLab.

Lyle Hanson's avatar
commented on merge request !36 "Dependency updates to eliminate vulnerabilities discovered by dependency-check" at adi-ia / uw-spring-security

This avoids warnings because ./target/ doesn't exist in multi-module projects, covers build artifacts for later jobs, and I think these dependency-...