Skip to content

Conversation

@ziltoidbot
Copy link

This PR contains the following updates:

Package Type Update Change
com.google.code.gson:gson compile patch 2.8.7 -> 2.8.9

GitHub Vulnerability Alerts

CVE-2022-25647

The package com.google.code.gson:gson before 2.8.9 is vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to denial of service attacks.


Release Notes

google/gson (com.google.code.gson:gson)

v2.8.9

v2.8.8


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@Stasky745 Stasky745 closed this Feb 20, 2025
@Stasky745 Stasky745 deleted the renovate/maven-com.google.code.gson-gson-vulnerability branch February 21, 2025 09:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants