[ 
https://issues.apache.org/jira/browse/CASSANDRA-19739?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17862409#comment-17862409
 ] 

Stefan Miklosovic commented on CASSANDRA-19739:
-----------------------------------------------

These dependencies were in cassandra-deps-tempalate which added them to a 
tarball. When added to cassandra-build-deps-template.xml.

I enumerated all of them in parent-pom-template.xml and updated to 1.78.

If we do not need this in the release tarball but just for the sake of tests, 
we can just move it to cassandra-build-deps-template.xml and be done with it.

[~jlewandowski] [~edimitrova] do we need this in the release tarball?

> Investigate bcprov-jdk18on-1.76.jar: CVE-2024-30172, CVE-2024-30171, 
> CVE-2024-29857, CVE-2024-34447
> ---------------------------------------------------------------------------------------------------
>
>                 Key: CASSANDRA-19739
>                 URL: https://issues.apache.org/jira/browse/CASSANDRA-19739
>             Project: Cassandra
>          Issue Type: Task
>          Components: Build
>            Reporter: Stefan Miklosovic
>            Assignee: Stefan Miklosovic
>            Priority: Normal
>             Fix For: 5.0-rc, 5.x
>
>
> This came up after I bumped dependency-check version to 10.0.0 as suggested 
> in CASSANDRA-19738.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscr...@cassandra.apache.org
For additional commands, e-mail: commits-h...@cassandra.apache.org

Reply via email to