2.2.4
What's Changed
- Add suppression to CVE-2022-33915 by @gfukushima in #155
- Remove suppression as the NVD has been updated to remove this false p… by @siladu in #156
- Update to jackson-databind to address CVE by @jframe in #157
- Upgrade protobufs to mitigate CVE-2022-3171 by @siladu in #158
- Disable parallelism for dependencyCheckAggregate to mitigate flakiness by @siladu in #159
- Upgrade azure keyvault to mitigate CVE-2022-31684 by @siladu in #160
- Upgrade grgit to 4.1.1 as 4.1.0 was failing to resolve by @siladu in #161
- Update protobuf library to fix CVE-2022-3509 by @jframe in #162
- Various dependencies versions update by @usmansaleem in #164
- Increase dependency check to use high cvss score by @jframe in #165
- Update netty to address CVE-2022-41881 and CVE-2022-41915 by @jframe in #166
- Use circle ci context for environment variables needed in tests by @jframe in #167
- Update circle contexts by @jframe in #170
- Various dependency upgrades by @siladu in #172
- Upgrade dependency-check-gradle plugin to 7.4.4 by @siladu in #174
- Fix hashicorp connection tests disabled in the previous commit by @siladu in #173
- Add signers context to nightly build by @jframe in #171
New Contributors
- @gfukushima made their first contribution in #155
Full Changelog: 2.2.3...2.2.4