SNOW-1196967 SNOW-1196966 Update vulnerable dependencies #720
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR updates dependencies identified by Snyk as vulnerable.
common-compress
- The SDK already using the fixed version, but due to Maven bug MNG-7982, the version is not propagated to the e2e test project. This PR declarescommon-compress
as a direct dependency to work around the issue.bouncycastle
- the Snyk-identified vulnerability doesn't seem to resolved even in the latest BC version, so we just upgrade BC to the latest version, and we will see if the warning disappears.