Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/run_tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ jobs:
with:
java-version: 14
- name: Cache Maven packages
uses: actions/cache@v2
uses: actions/cache@v4
with:
path: ~/.m2
key: ${{ runner.os }}-m2-${{ hashFiles('**/pom.xml') }}
Expand Down
4 changes: 2 additions & 2 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -451,7 +451,7 @@
<dependency>
<groupId>org.json</groupId>
<artifactId>json</artifactId>
<version>20220320</version>
<version>20231013</version>
</dependency>
<!-- test dependencies -->
<dependency>
Expand All @@ -473,7 +473,7 @@
<maven.compiler.target>${java.version}</maven.compiler.target>
<gson-fire-version>1.8.5</gson-fire-version>
<swagger-core-version>1.6.2</swagger-core-version>
<okhttp-version>4.9.1</okhttp-version>
<okhttp-version>4.9.2</okhttp-version>

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Action required

1. Some users retain vulnerable okhttp 🐞 Bug ⛨ Security

The Maven property now selects OkHttp 4.9.2, but the Gradle and SBT builds and both documented
Spring dependency overrides still select 4.9.1. Gradle or SBT builds retain the old version, and
Spring users following the instructions override the updated SDK dependency back to it.
Agent Prompt
## Issue description
The Maven OkHttp bump does not reach the alternate builds, and the documented Spring overrides force consumers back to 4.9.1.

## Fix Focus Areas
- pom.xml[476-476]
- build.gradle[109-110]
- build.sbt[13-14]
- README.md[60-76]
- MIGRATION.md[28-44]

## Recommended Fix
Update both OkHttp artifacts in the Gradle and SBT builds to 4.9.2, and change both Spring dependency examples in each guide to 4.9.2 so they no longer override the SDK's updated version.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

<gson-version>2.9.0</gson-version>
<commons-lang3-version>3.11</commons-lang3-version>
<jackson-databind-nullable-version>0.2.1</jackson-databind-nullable-version>
Expand Down
Loading