Skip to content

Conversation

dependabot-preview[bot]
Copy link
Contributor

Bumps hibernate-validator from 6.0.8.Final to 6.1.0.Final. This update includes security fixes.

Vulnerabilities fixed

Sourced from The GitHub Security Advisory Database.

Moderate severity vulnerability that affects org.hibernate.validator:hibernate-validator A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

Affected versions: < 6.0.18

Sourced from The GitHub Security Advisory Database.

Moderate severity vulnerability that affects org.hibernate.validator:hibernate-validator A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

Affected versions: < 6.1.0

Changelog

Sourced from hibernate-validator's changelog.

6.1.0.Final (25-10-2019)

** Bug * HV-1730 - engine - JavaBeanExecutable fails to initialize for enum type * HV-1715 - engine - Validation can sometimes proceed to the next group in sequence even after one of the constraints generated a violation

** Improvement * HV-1729 - performance - Skip allocation of an action for each need to access the context classloader

** Task * HV-1743 - build - Upgrade maven-compiler-plugin to 3.8.1 * HV-1742 - build - Upgrade to WildFly 18.0.0.Final * HV-1741 - build - Upgrade ByteBuddy test dependency to 1.10.2 * HV-1740 - engine - Deprecate @SafeHtml * HV-1739 - engine - CVE-2019-10219 Security issue with @SafeHtml * HV-1738 - build - Update Jackson test dependency to 2.9.10 * HV-1733 - tests - Fix locale settings of PredefinedScopeValidatorFactoryTest * HV-1732 - build - Change tarLongFileMode to posix for assembly building * HV-1731 - tck-runner - Move TCK signature check to tck-runner module * HV-1728 - build - Upgrade to WildFly 17.0.1.Final * HV-1727 - build - Update Jackson Databind test dependency to 2.9.9.2 * HV-1725 - build - Switch to using Jakarta EE artifacts * HV-1724 - build - Update to OpenJFX 11.0.2 * HV-1680 - engine - Avoid reflection by using instrumentation - build the enhancer

6.1.0.Alpha6 (19-07-2019)

** Bug * HV-1722 - engine - Remove settings-example.xml reference from .travis.yml * HV-1721 - engine - Take into account Hibernate Validator-specific configuration with PredefinedScopeValidatorFactoryImpl * HV-1720 - engine - Support bounded wildcard types in container value unwrapping

** New Feature * HV-1723 - validators - Provide a DigitsValidatorForMonetaryAmount to support @Digits on MonetaryAmounts

** Task * HV-1726 - engine - Make PredefinedScopeHibernateValidatorFactory extend HibernateValidatorFactory

6.1.0.Alpha5 (13-06-2019)

** Bug * HV-1713 - engine - Missing violation when a bean is validated with different groups * HV-1709 - validators - Polish Identification numbers are not considering length of the value * HV-1706 - validators - ISBN-13 algorithm does not handle checksum 10

** Improvement * HV-1719 - engine - Accept setting per-validator TraversableResolver with PredefinedScopeValidatorFactoryImpl

... (truncated)
Commits
  • 713964a [Jenkins release job] Preparing release 6.1.0.Final
  • 7ff5803 [Jenkins release job] changelog.txt updated by release build 6.1.0.Final
  • 77c9ca3 [Jenkins release job] README.md updated by release build 6.1.0.Final
  • 4194b02 HV-1740 Deprecate @SafeHtml for planned future removal
  • 124b7dd HV-1739 Fix CVE-2019-10219 Security issue with @SafeHtml
  • 2687d33 HV-1743 Upgrade maven-compiler-plugin to 3.8.1
  • 8b92994 HV-1742 Upgrade to WildFly 18.0.0.Final
  • ce6c698 HV-1741 Upgrade ByteBuddy test dependency to 1.10.2
  • b115bb6 HV-1725 Fix a few remaining things in the README.md
  • fdfa7ce HV-1725 Explicitly ban javax dependencies
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

Bumps [hibernate-validator](https://github.com/hibernate/hibernate-validator) from 6.0.8.Final to 6.1.0.Final. **This update includes security fixes.**
- [Release notes](https://github.com/hibernate/hibernate-validator/releases)
- [Changelog](https://github.com/hibernate/hibernate-validator/blob/master/changelog.txt)
- [Commits](hibernate/hibernate-validator@6.0.8.Final...6.1.0.Final)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
@dependabot-preview dependabot-preview bot added dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability labels Mar 23, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file security Pull requests that address a security vulnerability
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants