关于lib中依赖jar包的安全优化
envgap__didi__KnowStreaming-985
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
62f870a3421b973e1f918e2dbf8718c6e125119d- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
didi/KnowStreaming #985 · read the original issue
- [ ] 我已经在 [issues](https://github.com/didi/KnowStreaming/issues) 搜索过相关问题了,并没有重复的。 ## 在这里提出你的问题 这边安装了ks 最新的3.3 版本 服务器做了软件的安全扫描 发现安装了ks之后安全扫描了我们的jar发现lib里面很多jar版本都比较低有大量的安全风险 lib依赖的版本是否可以根据目前最新的来保持更新 或者有没有办法自行修复lib里面版本低的问题
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]