[Snyk] Security upgrade software.amazon.awssdk:sts from 2.10.56 to 2.48.4 - #762
[Snyk] Security upgrade software.amazon.awssdk:sts from 2.10.56 to 2.48.4#762chrislin22 wants to merge 1 commit into
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-IONETTY-18170202 - https://snyk.io/vuln/SNYK-JAVA-IONETTY-18170204
|
This is a minor version upgrade that spans a significant number of releases for the AWS SDK for Java v2. According to the official AWS SDK versioning policy, minor version updates are considered medium risk and may contain backward-incompatible changes. [7] Potential Risks:
While no specific, high-impact breaking API changes for the STS client were identified in the release notes, the large version gap and the SDK's versioning policy warrant a medium risk assessment. [7] Recommendation:
|
Snyk has created this PR to fix 2 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
pulsar-io/aws/pom.xmlVulnerabilities that will be fixed with an upgrade:
SNYK-JAVA-IONETTY-18170202
2.10.56->2.48.4No Path FoundProof of ConceptSNYK-JAVA-IONETTY-18170204
2.10.56->2.48.4No Path FoundProof of ConceptBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling