Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade undertow, report dependencies to GitHub #944

Merged
merged 1 commit into from
Feb 9, 2025

Conversation

erikvanoosten
Copy link
Contributor

@erikvanoosten erikvanoosten commented Feb 8, 2025

Undertow < 2.2.30.Final has multiple security alerts (e.g. https://github.com/zio/zio-streams-compress/security/dependabot/14). This upgrades Undertow to the fixed version.

Also add a workflow for reporting the dependencies to GitHub, allowing security warnings from GitHub.

As described on https://github.com/marketplace/actions/sbt-dependency-submission, before running the workflow, make sure that the Dependency Graph feature is enabled in the settings of your repository (Settings > Code Security and Analysis).
The graph of your sbt build will be visible in the Dependency Graph page of the Insights tab.

Undertow < 2.2.30.Final has multiple security alerts (e.g. https://github.com/zio/zio-streams-compress/security/dependabot/14). This upgrades Undertow to the fixed version.

Also add a workflow for reporting the dependencies to GitHub, allowing security warnings from GitHub.
Copy link
Contributor

@tgodzik tgodzik left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks!

@tgodzik tgodzik merged commit 369cdc1 into scalameta:main Feb 9, 2025
14 checks passed
@erikvanoosten
Copy link
Contributor Author

@tgodzik Thanks for merging. Please don't forget to enable the Dependency Graph feature in GitHub.

@tgodzik
Copy link
Contributor

tgodzik commented Feb 9, 2025

Ach, forgot it needed to be enabled, separately, thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants