From 57b62149b0cb827f21c7d87216481b2786baf61b Mon Sep 17 00:00:00 2001 From: broadbot Date: Mon, 11 Nov 2024 12:21:45 +0000 Subject: [PATCH] CORE-69: Update reactor-netty-http from 1.0.39 to 1.0.48 --- project/Dependencies.scala | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/project/Dependencies.scala b/project/Dependencies.scala index 52e32edad8..706b78810a 100644 --- a/project/Dependencies.scala +++ b/project/Dependencies.scala @@ -156,7 +156,7 @@ object Dependencies { // One reason to specify an override here is to avoid static-analysis security warnings. val transitiveDependencyOverrides = Seq( //Override for reactor-netty to address CVE-2023-34054 and CVE-2023-34062 - "io.projectreactor.netty" % "reactor-netty-http" % "1.0.39", + "io.projectreactor.netty" % "reactor-netty-http" % "1.0.48", // override commons-codec to address a non-CVE warning from DefectDojo "commons-codec" % "commons-codec" % "1.16.1" )