[DISCUSS] Upgrade vended guava version

2023-07-31 Thread Hong Teoh
Hi all, The current version of guava that is vended in Beam is com.google.guava:guava:26.0-jre. This version is really old, and has active vulnerabilities [1] [2] [1] https://mvnrepository.com/artifact/com.google.guava/guava/26.0-jre [2] CVE-2023-2976 https://cve.mitre.org/cgi-bin/cvename.cgi?na

Upgrade vended guava version

2023-07-31 Thread Hong Teoh
Hi all, The current version of guava that is vended in Beam is com.google.guava:guava:26.0-jre. This version is really old, and has active vulnerabilities [1] [2] [1] https://mvnrepository.com/artifact/com.google.guava/guava/26.0-jre [2] CVE-2023-2976 https://cve.mitre.org/cgi-bin/cvename.cgi?na

[DISCUSS] Upgrade vended guava version

2023-07-31 Thread Hong Teoh
Hi all, The current version of guava that is vended in Beam is com.google.guava:guava:26.0-jre. This version is really old, and has active vulnerabilities [1] [2] [1] https://mvnrepository.com/artifact/com.google.guava/guava/26.0-jre [2] CVE-2023-2976 https://cve.mitre.org/cgi-bin/cvename.cgi?na

[DISCUSS] Upgrade vended guava version

2023-07-31 Thread Hong Teoh
Hi all, The current version of guava that is vended in Beam is com.google.guava:guava:26.0-jre. This version is really old, and has active vulnerabilities [1] [2] [1] https://mvnrepository.com/artifact/com.google.guava/guava/26.0-jre [2] CVE-2023-2976 https://cve.mitre.org/cgi-bin/cvename.cgi?na