Skip to content

deps: upgrade commons-codec to 1.14#2164

Draft
lqiu96 wants to merge 1 commit into
mainfrom
fix-bug-496541059
Draft

deps: upgrade commons-codec to 1.14#2164
lqiu96 wants to merge 1 commit into
mainfrom
fix-bug-496541059

Conversation

@lqiu96

@lqiu96 lqiu96 commented Jun 22, 2026

Copy link
Copy Markdown
Member

[DRAFT]

Upgrades the transitive dependency commons-codec:commons-codec (brought in via httpclient) to 1.14 to resolve a security vulnerability (SNYK-JAVA-COMMONSCODEC-561518) which affects versions older than 1.14.

We cannot upgrade httpclient further because 4.5.14 is the latest version on the 4.x branch, and upgrading to 5.x would be a breaking change.

Reported via b/496541059

Upgrades the transitive dependency `commons-codec:commons-codec` (brought in via `httpclient`) to `1.14` to resolve a security vulnerability (SNYK-JAVA-COMMONSCODEC-561518) which affects versions older than 1.14.

We cannot upgrade httpclient further because 4.5.14 is the latest version on the 4.x branch, and upgrading to 5.x would be a breaking change.

BUG=496541059
TAG=agy
CONV=b43d61a6-175a-4130-8ed4-ec217f123c55
@product-auto-label product-auto-label Bot added the size: s Pull request size is small. label Jun 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size: s Pull request size is small.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant