-
Notifications
You must be signed in to change notification settings - Fork 0
Comparing changes
Open a pull request
base repository: lee4755026/Code4Java
base: master
head repository: luxiaoxun/Code4Java
compare: master
- 16 commits
- 4 files changed
- 4 contributors
Commits on May 23, 2023
-
Bump sqlite-jdbc from 3.7.2 to 3.41.2.2 in /MapHttpService
Bumps [sqlite-jdbc](https://github.com/xerial/sqlite-jdbc) from 3.7.2 to 3.41.2.2. - [Release notes](https://github.com/xerial/sqlite-jdbc/releases) - [Changelog](https://github.com/xerial/sqlite-jdbc/blob/master/CHANGELOG) - [Commits](xerial/sqlite-jdbc@sqlite-jdbc-3.7.2...3.41.2.2) --- updated-dependencies: - dependency-name: org.xerial:sqlite-jdbc dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 9489bd1 - Browse repository at this point
Copy the full SHA 9489bd1View commit details
Commits on Jun 14, 2023
-
Bump guava from 30.0-jre to 32.0.0-jre in /WebGisDemo
Bumps [guava](https://github.com/google/guava) from 30.0-jre to 32.0.0-jre. - [Release notes](https://github.com/google/guava/releases) - [Commits](https://github.com/google/guava/commits) --- updated-dependencies: - dependency-name: com.google.guava:guava dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 1249d66 - Browse repository at this point
Copy the full SHA 1249d66View commit details -
Bump guava from 30.1-jre to 32.0.0-jre in /MapHttpService
Bumps [guava](https://github.com/google/guava) from 30.1-jre to 32.0.0-jre. - [Release notes](https://github.com/google/guava/releases) - [Commits](https://github.com/google/guava/commits) --- updated-dependencies: - dependency-name: com.google.guava:guava dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 49af5cd - Browse repository at this point
Copy the full SHA 49af5cdView commit details -
Bump guava from 30.1-jre to 32.0.0-jre in /LogCollector
Bumps [guava](https://github.com/google/guava) from 30.1-jre to 32.0.0-jre. - [Release notes](https://github.com/google/guava/releases) - [Commits](https://github.com/google/guava/commits) --- updated-dependencies: - dependency-name: com.google.guava:guava dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for a6c6214 - Browse repository at this point
Copy the full SHA a6c6214View commit details -
Bump guava from 30.1-jre to 32.0.0-jre in /NettyMqService
Bumps [guava](https://github.com/google/guava) from 30.1-jre to 32.0.0-jre. - [Release notes](https://github.com/google/guava/releases) - [Commits](https://github.com/google/guava/commits) --- updated-dependencies: - dependency-name: com.google.guava:guava dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 945c78d - Browse repository at this point
Copy the full SHA 945c78dView commit details
Commits on Jun 19, 2023
-
Merge pull request luxiaoxun#35 from luxiaoxun/dependabot/maven/WebGi…
…sDemo/com.google.guava-guava-32.0.0-jre Bump guava from 30.0-jre to 32.0.0-jre in /WebGisDemo
Configuration menu - View commit details
-
Copy full SHA for 2b03f4e - Browse repository at this point
Copy the full SHA 2b03f4eView commit details -
Merge pull request luxiaoxun#36 from luxiaoxun/dependabot/maven/MapHt…
…tpService/com.google.guava-guava-32.0.0-jre Bump guava from 30.1-jre to 32.0.0-jre in /MapHttpService
Configuration menu - View commit details
-
Copy full SHA for fec21db - Browse repository at this point
Copy the full SHA fec21dbView commit details -
Merge pull request luxiaoxun#37 from luxiaoxun/dependabot/maven/LogCo…
…llector/com.google.guava-guava-32.0.0-jre Bump guava from 30.1-jre to 32.0.0-jre in /LogCollector
Configuration menu - View commit details
-
Copy full SHA for 34c2bec - Browse repository at this point
Copy the full SHA 34c2becView commit details -
Merge pull request luxiaoxun#38 from luxiaoxun/dependabot/maven/Netty…
…MqService/com.google.guava-guava-32.0.0-jre Bump guava from 30.1-jre to 32.0.0-jre in /NettyMqService
Configuration menu - View commit details
-
Copy full SHA for 3b938a9 - Browse repository at this point
Copy the full SHA 3b938a9View commit details
Commits on Nov 22, 2023
-
Bump org.elasticsearch:elasticsearch in /LogCollector
Bumps [org.elasticsearch:elasticsearch](https://github.com/elastic/elasticsearch) from 7.14.0 to 7.17.14. - [Release notes](https://github.com/elastic/elasticsearch/releases) - [Changelog](https://github.com/elastic/elasticsearch/blob/main/CHANGELOG.md) - [Commits](elastic/elasticsearch@v7.14.0...v7.17.14) --- updated-dependencies: - dependency-name: org.elasticsearch:elasticsearch dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for cf2b9bf - Browse repository at this point
Copy the full SHA cf2b9bfView commit details -
Bump org.elasticsearch:elasticsearch in /WebGisDemo
Bumps [org.elasticsearch:elasticsearch](https://github.com/elastic/elasticsearch) from 7.14.0 to 7.17.14. - [Release notes](https://github.com/elastic/elasticsearch/releases) - [Changelog](https://github.com/elastic/elasticsearch/blob/main/CHANGELOG.md) - [Commits](elastic/elasticsearch@v7.14.0...v7.17.14) --- updated-dependencies: - dependency-name: org.elasticsearch:elasticsearch dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 7352c58 - Browse repository at this point
Copy the full SHA 7352c58View commit details
Commits on Dec 17, 2023
-
vuln-fix: Use HTTPS instead of HTTP to resolve deps CVE-2021-26291
This fixes a security vulnerability in this project where the `pom.xml` files were configuring Maven to resolve dependencies over HTTP instead of HTTPS. Weakness: CWE-829: Inclusion of Functionality from Untrusted Control Sphere Severity: High CVSS: 8.1 Detection: CodeQL & OpenRewrite (https://app.moderne.io/recipes/org.openrewrite.maven.security.UseHttpsForRepositories) Reported-by: Jonathan Leitschuh <[email protected]> Signed-off-by: Jonathan Leitschuh <[email protected]> Bug-tracker: JLLeitschuh/security-research#8 Detection: CodeQL (https://codeql.github.com/codeql-query-help/java/java-maven-non-https-url/) & OpenRewrite (https://app.moderne.io/recipes/org.openrewrite.maven.security.UseHttpsForRepositories) Reported-by: Jonathan Leitschuh <[email protected]> Signed-off-by: Jonathan Leitschuh <[email protected]> Bug-tracker: JLLeitschuh/security-research#8 Use this link to re-run the recipe: https://app.moderne.io/recipes/builder/IfHkrYfxx?organizationId=QWxsIEdpdEh1Yg%3D%3D Co-authored-by: Moderne <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 1b5532e - Browse repository at this point
Copy the full SHA 1b5532eView commit details
Commits on Jan 31, 2024
-
Merge pull request luxiaoxun#44 from BulkSecurityGeneratorProjectV2/f…
…ix/JLL/use_https_to_resolve_dependencies_maven [SECURITY] Use HTTPS to resolve dependencies in Maven Build
Configuration menu - View commit details
-
Copy full SHA for 3c2bafc - Browse repository at this point
Copy the full SHA 3c2bafcView commit details
Commits on Feb 2, 2024
-
Merge pull request luxiaoxun#43 from luxiaoxun/dependabot/maven/WebGi…
…sDemo/org.elasticsearch-elasticsearch-7.17.14 Bump org.elasticsearch:elasticsearch from 7.14.0 to 7.17.14
Configuration menu - View commit details
-
Copy full SHA for e116227 - Browse repository at this point
Copy the full SHA e116227View commit details -
Merge pull request luxiaoxun#42 from luxiaoxun/dependabot/maven/LogCo…
…llector/org.elasticsearch-elasticsearch-7.17.14 Bump org.elasticsearch:elasticsearch from 7.14.0 to 7.17.14
Configuration menu - View commit details
-
Copy full SHA for aa6fbf0 - Browse repository at this point
Copy the full SHA aa6fbf0View commit details -
Merge pull request luxiaoxun#34 from luxiaoxun/dependabot/maven/MapHt…
…tpService/org.xerial-sqlite-jdbc-3.41.2.2 Bump sqlite-jdbc from 3.7.2 to 3.41.2.2
Configuration menu - View commit details
-
Copy full SHA for 99c2d13 - Browse repository at this point
Copy the full SHA 99c2d13View commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff master...master