Skip to content

Commit 06e68d5

Browse files
committed
update transitive dep for CVE
1 parent 9c8a1ea commit 06e68d5

File tree

3 files changed

+17
-1
lines changed

3 files changed

+17
-1
lines changed

CHANGELOG.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,8 @@ Changelog
33

44
*Also see [Tools and installer changelog](https://github.com/clojure/brew-install/blob/1.12.0/CHANGELOG.md)*
55

6+
* next
7+
* Update dependencies
68
* 0.24.1529 on Aug 14, 2025
79
* TDEPS-259 Improve error reporting on deps.edn spec errors
810
* Use latest tools.deps.cli in root deps.edn

deps.edn

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,9 @@
22
:deps {
33
org.clojure/clojure {:mvn/version "1.12.1"}
44
org.apache.maven.resolver/maven-resolver-api {:mvn/version "1.8.2"}
5-
org.apache.maven.resolver/maven-resolver-spi {:mvn/version "1.8.2"}
5+
org.apache.maven.resolver/maven-resolver-spi {:mvn/version "1.8.2" :exclusions [org.apache.commons/commons-lang3]}
6+
;; override for CVE
7+
org.apache.commons/commons-lang3 {:mvn/version "3.18.0"}
68
org.apache.maven.resolver/maven-resolver-impl {:mvn/version "1.8.2"}
79
org.apache.maven.resolver/maven-resolver-util {:mvn/version "1.8.2"}
810
org.apache.maven.resolver/maven-resolver-connector-basic {:mvn/version "1.8.2"}

pom.xml

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,6 +38,18 @@
3838
<groupId>org.apache.maven.resolver</groupId>
3939
<artifactId>maven-resolver-api</artifactId>
4040
<version>${resolverVersion}</version>
41+
<exclusions>
42+
<exclusion>
43+
<groupId>org.apache.commons</groupId>
44+
<artifactId>commons-lang3</artifactId>
45+
</exclusion>
46+
</exclusions>
47+
</dependency>
48+
<!-- override for cve -->
49+
<dependency>
50+
<groupId>org.apache.commons</groupId>
51+
<artifactId>commons-lang3</artifactId>
52+
<version>3.18.0</version>
4153
</dependency>
4254
<dependency>
4355
<groupId>org.apache.maven.resolver</groupId>

0 commit comments

Comments
 (0)