Commit 5b5dfee
authored
fix(common): Bump assertj-core from 3.9.1 to 3.27.7 (opensearch-project#5294)
Addresses CVE-2026-24400 (GHSA-rqfh-9r24-8c9r), an XXE vulnerability
in AssertJ's isXmlEqualTo assertion when parsing untrusted XML. While
the vulnerable method is not used in this codebase and assertj-core is
test-scoped only, this bump resolves the security scanner finding on
the 2.19 branch.
Signed-off-by: Chen Dai <daichen@amazon.com>1 parent 9d35e71 commit 5b5dfee
1 file changed
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
48 | | - | |
| 48 | + | |
49 | 49 | | |
50 | 50 | | |
51 | 51 | | |
| |||
0 commit comments