Title: Dependency version updates · Issue #3239 · graphql-java/graphql-java · GitHub
Open Graph Title: Dependency version updates · Issue #3239 · graphql-java/graphql-java
X Title: Dependency version updates · Issue #3239 · graphql-java/graphql-java
Description: Summary Even though this is about a Guava vulnerability, because graphql-java shades the Guava library, vulnerabilities-scanning software is flagging graphql-java as also being vulnerable. If I understand correctly, Guava has been update...
Open Graph Description: Summary Even though this is about a Guava vulnerability, because graphql-java shades the Guava library, vulnerabilities-scanning software is flagging graphql-java as also being vulnerable. If I und...
X Description: Summary Even though this is about a Guava vulnerability, because graphql-java shades the Guava library, vulnerabilities-scanning software is flagging graphql-java as also being vulnerable. If I und...
Opengraph URL: https://github.com/graphql-java/graphql-java/issues/3239
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Dependency version updates","articleBody":"### Summary\r\n\r\nEven though this is about a Guava vulnerability, because graphql-java shades the Guava library, vulnerabilities-scanning software is flagging graphql-java as also being vulnerable.\r\n\r\nIf I understand correctly, Guava has been updated already in graphql-java, but a \"stable\" release has not been made yet(?).\r\nI am creating this ticket to ask if you could release a patch version including this update.\r\n\r\nThe Guava vulnerability reported at CVE-2023-2976 has been fixed in Guava version 32.0.0.\r\nThe latest stable version of graphql-java seems to be 20.3 as of writing, but that version is using Guava 31.0.1-jre.\r\n\r\nThe CVE is not published as of writing. But it's referenced in Guava's [CHANGELOG](https://github.com/google/guava/releases).\r\n\r\nThe impact of the Guava vulnerability is explained [here](https://github.com/advisories/GHSA-5mg8-w23w-74h3).\r\n","author":{"url":"https://github.com/renatoathaydes","@type":"Person","name":"renatoathaydes"},"datePublished":"2023-06-02T10:11:28.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":8},"url":"https://github.com/3239/graphql-java/issues/3239"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:40c333b2-6cfe-36f1-45cc-9332ae284863 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | AB80:129F7F:19FE45:22B18F:6A616B00 |
| html-safe-nonce | 00528faef3565a05520ef6d0f01589dd9d419e8cc12d6a7c216e50a1b1a5a4a5 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJBQjgwOjEyOUY3RjoxOUZFNDU6MjJCMThGOjZBNjE2QjAwIiwidmlzaXRvcl9pZCI6IjI0ODc3MTkwNzQ3OTkzODEyNDgiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | abd7e5984082d2c5b423d28a0f816c6d5120b4c0e8683e93f62ab856133f9ef6 |
| hovercard-subject-tag | issue:1737895590 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/graphql-java/graphql-java/3239/issue_layout |
| twitter:image | https://opengraph.githubassets.com/0352a94056e10a07961fca2dcc3452a23f6cce7c8dfa14811d4e8e6d6174184e/graphql-java/graphql-java/issues/3239 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/0352a94056e10a07961fca2dcc3452a23f6cce7c8dfa14811d4e8e6d6174184e/graphql-java/graphql-java/issues/3239 |
| og:image:alt | Summary Even though this is about a Guava vulnerability, because graphql-java shades the Guava library, vulnerabilities-scanning software is flagging graphql-java as also being vulnerable. If I und... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | renatoathaydes |
| hostname | github.com |
| expected-hostname | github.com |
| None | a69385f7d268ece7ad25b131bbd70f457024811fc79afcae43785a6849b724e2 |
| turbo-cache-control | no-preview |
| go-import | github.com/graphql-java/graphql-java git https://github.com/graphql-java/graphql-java.git |
| octolytics-dimension-user_id | 14289921 |
| octolytics-dimension-user_login | graphql-java |
| octolytics-dimension-repository_id | 38602457 |
| octolytics-dimension-repository_nwo | graphql-java/graphql-java |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 38602457 |
| octolytics-dimension-repository_network_root_nwo | graphql-java/graphql-java |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 484cf265a1f970d5c7a5e7c37cb677d8010aa12f |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width