Skip to content

MLE-30953 MLE-30952 Vulnerability fixes#1952

Open
jonmille wants to merge 2 commits into
developfrom
MLE-30953
Open

MLE-30953 MLE-30952 Vulnerability fixes#1952
jonmille wants to merge 2 commits into
developfrom
MLE-30953

Conversation

@jonmille

Copy link
Copy Markdown

Copilot AI review requested due to automatic review settings June 26, 2026 13:54

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates dependency versions/constraints in the Gradle build to address reported vulnerabilities in the Java client library build.

Changes:

  • Bump logbackVersion in gradle.properties.
  • Add Gradle resolutionStrategy.force entries to pin OpenTelemetry API/context versions.

Reviewed changes

Copilot reviewed 1 out of 2 changed files in this pull request and generated 1 comment.

File Description
gradle.properties Updates the shared Logback version property used by modules/tests.
build.gradle Forces specific OpenTelemetry artifact versions during dependency resolution to mitigate CVEs.

Comment thread gradle.properties
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants