Skip to content

Conversation

trask
Copy link
Member

@trask trask commented Aug 19, 2025

This does reduce the version of azure-identity from 1.16.3 back to 1.16.2, but I think that's ok given that update was just due to us merging a dependabot PR (#4386), and wasn't part of the original pinning.

Running OWASP on this branch to check: https://github.com/trask/ApplicationInsights-Java/actions/runs/17077701328

@trask
Copy link
Member Author

trask commented Aug 19, 2025

Closing, looks like we do need 1.16.3:

nimbus-jose-jwt-10.0.1.jar/META-INF/maven/com.google.code.gson/gson/pom.xml (pkg:maven/com.google.code.gson/gson@2.11.0, cpe:2.3:a:google:gson:2.11.0:*:*:*:*:*:*:*) : CVE-2025-53864

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant