Code Monkey home page Code Monkey logo

Comments (7)

codefromthecrypt avatar codefromthecrypt commented on August 23, 2024

thanks for raising the issue. All CVEs that can be easily remedied will be done in the next few days and cut as a patch release.

Meanwhile, I'm trying to get a better understanding of current users. What configuration of zipkin do you run? Feel free to reply here or on gitter https://app.gitter.im/#/room/#openzipkin_zipkin:gitter.im

from zipkin.

0yukkey0 avatar 0yukkey0 commented on August 23, 2024

@codefromthecrypt

Thanks for the reply.
I understand that it will be fixed soon. Looking forward to it.

I am also using the zipkin-server jar on the server where the SpringBoot application is deployed.

from zipkin.

codefromthecrypt avatar codefromthecrypt commented on August 23, 2024

can you verify the master build addresses this CVE and also mention how you are validating CVEs?

from zipkin.

0yukkey0 avatar 0yukkey0 commented on August 23, 2024

We use a service called Snyk to verify vulnerabilities.

We detected this when verifying with Snyk against the bundled spring boot and zipkin.
We checked the contents of the zipkin jar and found that it was a CVE-unsupported version.

from zipkin.

codefromthecrypt avatar codefromthecrypt commented on August 23, 2024

ok thanks. are you able to test the current 2.24.4-SNAPSHOT (master) version prior to release?

from zipkin.

0yukkey0 avatar 0yukkey0 commented on August 23, 2024

I saw the PR for the version update. Thanks.

I also confirmed that the version of the library contained in the jar created by building the master locally is updated.
Also, the snapshot version of the jar cleared the snyk check.

from zipkin.

codefromthecrypt avatar codefromthecrypt commented on August 23, 2024

thanks for the help and attention! we'll release a patch tomorrow.

from zipkin.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.