Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Backport 1.x] Corrects CVE-2023-20863 by forcing spring-expression version #2712

Merged
merged 1 commit into from
Apr 20, 2023

Conversation

opensearch-trigger-bot[bot]
Copy link
Contributor

Backport 87c8e46 from #2711

Signed-off-by: Stephen Crawford <[email protected]>
(cherry picked from commit 87c8e46)
@stephen-crawford
Copy link
Contributor

The snakeyaml dependencies were introduced as part of: https://github.com/opensearch-project/security/pull/2691/checks?check_run_id=12812796814 so going to merge this and then see if we can do anything about them.

@stephen-crawford stephen-crawford merged commit 16a67fb into 1.x Apr 20, 2023
@stephen-crawford stephen-crawford deleted the backport/backport-2711-to-1.x branch April 20, 2023 18:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants