Sitelet https://github.com/grpc/grpc-java/pull/7613
Skip to content

Fix for https://github.com/grpc/grpc-java/issues/7612, increasing the… - #7613

Merged
ericgribkoff merged 1 commit into
grpc:masterfrom
attila123:issue_7612_fix
Nov 12, 2020
Merged

ericgribkoff merged 1 commit into
grpc:masterfrom
attila123:issue_7612_fix

Conversation

@attila123

Copy link
Copy Markdown
Contributor

… google auth library version to 0.22.0 to use the latest non-vulnerable apache httpclient 4.5.13

….0 to use the latest non-vulnerable apache httpclient 4.5.13
@linux-foundation-easycla

Copy link
Copy Markdown

CLA Not Signed

@attila123

Copy link
Copy Markdown
Contributor Author

I signed the EasyCLA 2 times, no luck. Created support ticket: https://jira.linuxfoundation.org/plugins/servlet/theme/portal/4/SUPPORT-2973

@ericgribkoff ericgribkoff added the kokoro:run Add this label to a PR to tell Kokoro the code is safe and tests can be run label Nov 11, 2020
@ericgribkoff

Copy link
Copy Markdown
Contributor

The change seems alright to me. FWIW went through the history of the linked repos from #7612 and it looks like the actual transitive dependency update that this PR is interested in bringing in (google http client 1.37.0 updating to apache httpclient 4.5.13) was not in response to any vulnerability but just a regularly scheduled upgrade: googleapis/google-http-java-client#1134

@ericgribkoff
ericgribkoff requested a review from ejona86 November 11, 2020 20:59
@ejona86

ejona86 commented Nov 11, 2020

Copy link
Copy Markdown
Member

Looks like the CLA issue has been resolved. It is green.

@ejona86 ejona86 added kokoro:run Add this label to a PR to tell Kokoro the code is safe and tests can be run and removed kokoro:run Add this label to a PR to tell Kokoro the code is safe and tests can be run labels Nov 11, 2020
@grpc-kokoro grpc-kokoro removed the kokoro:run Add this label to a PR to tell Kokoro the code is safe and tests can be run label Nov 11, 2020
@ericgribkoff
ericgribkoff merged commit 8062b69 into grpc:master Nov 12, 2020
@ericgribkoff

Copy link
Copy Markdown
Contributor

@attila123 Thanks!

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants