-
Notifications
You must be signed in to change notification settings - Fork 1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerability report on dependency: com.squareup.okhttp3/logging-interceptor #1718
Comments
Upstream reference: fabric8io/kubernetes-client#6344 |
Fabric8 Kubernetes 7.0.0 has been released, but it looks like it missed Spring Cloud Kubernetes 3.2.0. Any chance to have the bump still in 3.2? |
No we cannot make a major change to a dependency in a minor of sc-kubernetes. We would need to do this in a major. We could ask them to backport it to the version of fabric8 we are using in 3.2 and see if they will do a release, then we can pick that up. |
Thanks for the feedback! So upgrade to Fabric8 Kubernetes 7.0 has to wait for Spring Cloud Kubernetes 4.0? Frameworks like Java Operator SDK are adopting Fabric8 Kubernetes 7.0 already and an estimation for this to happen in Spring Cloud would be useful to lay out roadmaps for projects using both. |
The current plan is to have a GA release of our next major in November. See https://spring.io/blog/2024/10/01/from-spring-framework-6-2-to-7-0 |
We have received a notification for a vulnerability in our project using
spring-cloud-kubernetes-fabric8-config:jar:3.1.3
. Details follow.Vulnerabilities in: pkg:maven/com.squareup.okhttp3/[email protected] [CVE-2023-0833] (owasp)
currently there is not released version from
io.fabric8:kubernetes-client
with fixes on the reported dependency.The text was updated successfully, but these errors were encountered: