Skip to content

fix(sec): upgrade com.thoughtworks.xstream:xstream to 1.4.20#426

Closed
smart2pet wants to merge 1 commit intokekingcn:masterfrom
smart2pet:oscs_fix_cevq1t8au51u0ah91cbg
Closed

fix(sec): upgrade com.thoughtworks.xstream:xstream to 1.4.20#426
smart2pet wants to merge 1 commit intokekingcn:masterfrom
smart2pet:oscs_fix_cevq1t8au51u0ah91cbg

Conversation

@smart2pet
Copy link
Copy Markdown

What happened?

There are 1 security vulnerability found in com.thoughtworks.xstream:xstream 1.4.19

What did I do?

Upgrade com.thoughtworks.xstream:xstream from 1.4.19 to 1.4.20 for vulnerability fix

What did you expect to happen?

Ideally, no insecure libs should be used.

The specification of the pull request

PR Specification from OSCS

@klboke
Copy link
Copy Markdown
Contributor

klboke commented Mar 3, 2026

感谢提交。

这个 PR 当前不直接合并:分支基线与当前 master 偏差较大,直接合并会引入大量与本次主题无关的历史改动,回归风险高。

建议基于最新 master 重新提交小粒度 PR(仅保留本问题相关改动),并附最小验证说明。

@klboke klboke closed this Mar 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants