Skip to content

Upgrade AWS SDK v2 to 2.30 and other dependencies to fix high CVEs#451

Open
ezhang6811 wants to merge 3 commits intomasterfrom
cve-fixes
Open

Upgrade AWS SDK v2 to 2.30 and other dependencies to fix high CVEs#451
ezhang6811 wants to merge 3 commits intomasterfrom
cve-fixes

Conversation

@ezhang6811
Copy link
Contributor

@ezhang6811 ezhang6811 commented Mar 26, 2026

Issue #, if available:

Description of changes:
The daily scan workflow detected several CVEs. This PR upgrades the offending dependencies to resolve them.

Dependency upgrades

Verification

Trivy HIGH scan verified locally: published to Maven local, extracted JARs, ran trivy fs with the trivyignore file. 0 high findings.
Modified an SQS test to match the JSON protocol expected by the MessageMD5ChecksumInterceptorin the mock response.

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@ezhang6811 ezhang6811 requested a review from a team as a code owner March 26, 2026 20:57
@ezhang6811 ezhang6811 changed the title fix high CVEs from daily scan Upgrade AWS SDK to 2.30 and other dependencies to fix high CVEs Mar 26, 2026
@ezhang6811 ezhang6811 changed the title Upgrade AWS SDK to 2.30 and other dependencies to fix high CVEs Upgrade AWS SDK v2 to 2.30 and other dependencies to fix high CVEs Mar 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants