Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.
Changes included in this PR
- Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
Vulnerabilities that will be fixed
With an upgrade:
Severity |
Priority Score (*) |
Issue |
Upgrade |
Breaking Change |
Exploit Maturity |
![medium severity medium severity]() |
539/1000
Why? Has a fix available, CVSS 6.5 |
Improper Input Validation
SNYK-JAVA-ORGAPACHEHTTPCOMPONENTS-1016906 |
org.apache.jena:apache-jena-libs:
3.14.0 -> 3.17.0
|
No |
No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
![]()
🧐
View latest project report
🛠
Adjust project settings
📚
Read more about Snyk's upgrade and patch logic
You can view, comment on, or merge this pull request online at:
https://github.com/eclipse/lyo.server/pull/44
Commit Summary
- fix: pom.xml to reduce vulnerabilities
File Changes
Patch Links:
—
You are receiving this because you are subscribed to this thread.
Reply to this email directly,
view it on GitHub, or
unsubscribe.![]()