Skip to content

Conversation

@jtwing62173
Copy link
Contributor

Fix for the Severe vulnerability in the Maven plugin shared library, per Issue reported.

#326

This contains a fix that builds and passes tests. When's the next release? :-)

@jtwing62173
Copy link
Contributor Author

Whoa, hey, the Sonar fail isn't my fault; nothing I changed had any impact on the Sonar scan. might be that it's trying to reach across to my forked repo and can't access because it doesn't have credentials for it. If that's the case, I'm very willing to add the service account you're using to run Sonar, to the forked repo's config.

Alternately, I really like this plugin; I'm willing to be a contributor to more than just config changes. If you're interested in / willing to have additional contributors, I'd love to join the project. My company for many years didn't allow OSS contributions, but they recently changed the policy. I have 20 years of Java experience to offer... :-)

Copy link
Owner

@kobylynskyi kobylynskyi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@jtwing62173 thanks for the contribution!
I will release this change as part of 3.1.1 soon.

@kobylynskyi kobylynskyi merged commit fae8ffb into kobylynskyi:master Sep 25, 2020
@kobylynskyi kobylynskyi self-assigned this Sep 25, 2020
@kobylynskyi kobylynskyi linked an issue Sep 25, 2020 that may be closed by this pull request
@kobylynskyi
Copy link
Owner

@jtwing62173, version 3.1.1 with your fix was released today. Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CVSS vulnerability detected - can you up-level the offending lib?

2 participants