Skip to content

Update HTTP client dependencies#3

Merged
jbuncle merged 1 commit intomasterfrom
security/update-http-dependencies
Mar 29, 2026
Merged

Update HTTP client dependencies#3
jbuncle merged 1 commit intomasterfrom
security/update-http-dependencies

Conversation

@jbuncle
Copy link
Copy Markdown
Owner

@jbuncle jbuncle commented Mar 29, 2026

Summary:

  • update commons-codec from 1.10 to 1.18.0
  • update commons-io from 2.4 to 2.20.0
  • update httpcore from 4.4.3 to 4.4.16
  • update httpclient from 4.5.1 to 4.5.14

Why:
This repo ships old runtime HTTP and IO libraries. In particular, Apache HttpClient 4.5.1 is on a line affected by published security issues, so this moves the project onto maintained versions.

Verification:

  • built locally with udocker using Maven
  • relied on existing GitHub Actions validation for the repo

@jbuncle jbuncle merged commit f3f26f6 into master Mar 29, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant