Skip to content

upgrade dependencies#353

Open
qiangdavidliu wants to merge 1 commit intoNetflix:masterfrom
qiangdavidliu:master
Open

upgrade dependencies#353
qiangdavidliu wants to merge 1 commit intoNetflix:masterfrom
qiangdavidliu:master

Conversation

@qiangdavidliu
Copy link
Copy Markdown
Contributor

No description provided.

@qiangdavidliu
Copy link
Copy Markdown
Contributor Author

@spencergibb

@spencergibb
Copy link
Copy Markdown

You guys and changing java versions in a minor :-)

@spencergibb
Copy link
Copy Markdown

So is this after 2.2.3?

@qiangdavidliu
Copy link
Copy Markdown
Contributor Author

qiangdavidliu commented Oct 31, 2017

Yeah, unfortunately due to some decisions from a long time ago :(.
This PR is still probationary, no need to merge it in now. At some point in the future we'd like to bump the ribbon dependencies to be more inline with what we actually use.
If you guys have a preference, we can do this later.

@spencergibb
Copy link
Copy Markdown

NP, can you at least bump the ribbon version to 2.3.x so the 2.2.x line stays java 7?

@qiangdavidliu
Copy link
Copy Markdown
Contributor Author

No worries. If/when the java8 does happen, it will absolutely be 2.3.x.

@wojteo
Copy link
Copy Markdown

wojteo commented Nov 3, 2021

Is there a chance for these dependencies to be upgraded? There are several highly scored CVEs present in there
You could consider dependabot to make this update process more automated in the future
#452 #491

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants