Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

upgrade dependencies #353

Open
wants to merge 1 commit into
base: master
Choose a base branch
from
Open

upgrade dependencies #353

wants to merge 1 commit into from

Conversation

qiangdavidliu
Copy link
Contributor

No description provided.

@qiangdavidliu
Copy link
Contributor Author

@spencergibb

@spencergibb
Copy link

You guys and changing java versions in a minor :-)

@spencergibb
Copy link

So is this after 2.2.3?

@qiangdavidliu
Copy link
Contributor Author

qiangdavidliu commented Oct 31, 2017

Yeah, unfortunately due to some decisions from a long time ago :(.
This PR is still probationary, no need to merge it in now. At some point in the future we'd like to bump the ribbon dependencies to be more inline with what we actually use.
If you guys have a preference, we can do this later.

@spencergibb
Copy link

NP, can you at least bump the ribbon version to 2.3.x so the 2.2.x line stays java 7?

@qiangdavidliu
Copy link
Contributor Author

No worries. If/when the java8 does happen, it will absolutely be 2.3.x.

@wojteo
Copy link

wojteo commented Nov 3, 2021

Is there a chance for these dependencies to be upgraded? There are several highly scored CVEs present in there
You could consider dependabot to make this update process more automated in the future
#452 #491

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants