From 0a43aa0b4e3001dbf35e9a8b56df3eeed90c141f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 29 Jan 2025 13:38:46 +0000 Subject: [PATCH] Chore(deps): Bump com.google.protobuf:protobuf-java Bumps [com.google.protobuf:protobuf-java](https://github.com/protocolbuffers/protobuf) from 3.25.5 to 4.29.3. - [Release notes](https://github.com/protocolbuffers/protobuf/releases) - [Changelog](https://github.com/protocolbuffers/protobuf/blob/main/protobuf_release.bzl) - [Commits](https://github.com/protocolbuffers/protobuf/commits) --- updated-dependencies: - dependency-name: com.google.protobuf:protobuf-java dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- gradle/libs.versions.toml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/gradle/libs.versions.toml b/gradle/libs.versions.toml index 01b202d..5850340 100644 --- a/gradle/libs.versions.toml +++ b/gradle/libs.versions.toml @@ -15,7 +15,7 @@ spring-boot-starter-web = { module = "org.springframework.boot:spring-boot-start spring-boot-starter-test = { module = "org.springframework.boot:spring-boot-starter-test" } spring-cloud-starter-kubernetes-client-config = "org.springframework.cloud:spring-cloud-starter-kubernetes-client-config:3.2.0" #pin transient client-config protobuf dependency version to avoid CVE-2024-7254 -google-java-protobuf = "com.google.protobuf:protobuf-java:3.25.5" +google-java-protobuf = "com.google.protobuf:protobuf-java:4.29.3" spring-security-test = { module = "org.springframework.security:spring-security-test" } fitko-fitconnect-sdk = "dev.fitko.fitconnect.sdk:client:2.5.0" [plugins]