Skip to content

Update assertj-core to 3.27.7#2

Merged
hcoles merged 2 commits into
pitest:mainfrom
alangdundee:main
May 15, 2026
Merged

Update assertj-core to 3.27.7#2
hcoles merged 2 commits into
pitest:mainfrom
alangdundee:main

Conversation

@alangdundee

Copy link
Copy Markdown
Contributor

Assertj-core 3.14.0->3.27.7

When updating to the newest version of pitest 1.23.x, the newly separated pitest-history-plugin project was required.

When configuring this, it was noticed that project has a flagged vulnerable dependency.

https://mvnrepository.com/artifact/org.pitest/pitest-history-plugin/0.0.1

"Vulnerabilities Vulnerabilities from dependencies: CVE-2026-24400"

This is from the assertj dependency:

https://mvnrepository.com/artifact/org.pitest/pitest-history-plugin/0.0.1/dependencies

It is unknown if the vulnerability would surface through the plugin.
First time visitors seeing a single release, version lower than 1.0, and a vulnerability flagged on it may have been hesitant to investigate further.

alangdundee and others added 2 commits May 4, 2026 17:04
Assertj-core 3.14.0->3.27.7

When updating to the newest version of pitest 1.23.x, the newly separated `pitest-history-plugin` project was required.

When configuring this, it was noticed that project has a flagged vulnerable dependency.

https://mvnrepository.com/artifact/org.pitest/pitest-history-plugin/0.0.1

"Vulnerabilities Vulnerabilities from dependencies: CVE-2026-24400"

This is from the assertj dependency:

https://mvnrepository.com/artifact/org.pitest/pitest-history-plugin/0.0.1/dependencies

It is unknown if the vulnerability would surface through the plugin.
First time visitors seeing a single release, version lower than 1.0, and a vulnerability flagged on it may have been hesitant to investigate further.
Comment thread pom.xml
@luisgomez29

Copy link
Copy Markdown

@hcoles Hi! Any updates on the review? Thanks!

@hcoles

hcoles commented May 15, 2026

Copy link
Copy Markdown
Contributor

Hi @luisgomez29

Apologies, I didn't see this when it came in. Github seems to be having issues just now, but I'll merge when they resolve.

@hcoles hcoles merged commit d6f0264 into pitest:main May 15, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants