Skip to content

Commit

Permalink
[Java] Upgrade Commons-io to 2.14 (ray-project#44437)
Browse files Browse the repository at this point in the history
<!-- Thank you for your contribution! Please review
https://github.com/ray-project/ray/blob/master/CONTRIBUTING.rst before
opening a pull request. -->

<!-- Please add a reviewer to the assignee section when you create a PR.
If you don't have the access to it, we will shortly find a reviewer and
assign them to your PR. -->

## Why are these changes needed?

[Java] Upgrade Commons-io to 2.14

commons-io can be upgraded to 2.14.0. commons-io 2.7 is an older
version. commons-io 2.14.0 has been verified for a long time and has no
direct or indirect CVE issues.

## Related issue number

<!-- For example: "Closes ray-project#1234" -->

## Checks

- [x] I've signed off every commit(by using the -s flag, i.e., `git
commit -s`) in this PR.
- [ ] I've run `scripts/format.sh` to lint the changes in this PR.
- [ ] I've included any doc changes needed for
https://docs.ray.io/en/master/.
- [ ] I've added any new APIs to the API Reference. For example, if I
added a
method in Tune, I've added it in `doc/source/tune/api/` under the
           corresponding `.rst` file.
- [ ] I've made sure the tests are passing. Note that there might be a
few flaky tests, see the recent failures at https://flakey-tests.ray.io/
- Testing Strategy
   - [ ] Unit tests
   - [ ] Release tests
   - [ ] This PR is not tested :(

Signed-off-by: Shilun Fan <[email protected]>
Co-authored-by: Thomas Desrosiers <[email protected]>
  • Loading branch information
2 people authored and JP-sDEV committed Nov 14, 2024
1 parent e85f3d1 commit 6522ef8
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion java/dependencies.bzl
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ def gen_java_deps():
"com.sun.xml.bind:jaxb-core:2.3.0",
"com.sun.xml.bind:jaxb-impl:2.3.0",
"com.typesafe:config:1.3.2",
"commons-io:commons-io:2.7",
"commons-io:commons-io:2.14.0",
"de.ruedigermoeller:fst:2.57",
"javax.xml.bind:jaxb-api:2.3.0",
"javax.activation:activation:1.1.1",
Expand Down

0 comments on commit 6522ef8

Please sign in to comment.