Uh oh!
There was an error while loading. Please reload this page.
[Snyk] Security upgrade io.dapr:dapr-sdk from 1.8.0 to 1.17.5 - #60
[Snyk] Security upgrade io.dapr:dapr-sdk from 1.8.0 to 1.17.5#60benjaminhuo wants to merge 1 commit into
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366
benjaminhuo
commented
Jul 21, 2026
This upgrade spans multiple minor versions and includes several significant updates, most notably the stabilization of the Bulk PubSub API in version 1.17.0. Key Changes:
Recommendation: Developers should review their usage of the Bulk PubSub API. If the alpha version is being used, code must be updated to use the stable Source: Dapr v1.17 Release Notes, Dapr v1.15 Release Highlights
|
CLAassistant
commented
Jul 21, 2026
|
Snyk has created this PR to fix 2 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
functions-framework-invoker/pom.xmlVulnerabilities that will be fixed with an upgrade:
SNYK-JAVA-COMFASTERXMLJACKSONCORE-17440598
1.8.0->1.17.5Proof of ConceptSNYK-JAVA-COMFASTERXMLJACKSONCORE-17440366
1.8.0->1.17.5No Known ExploitBreaking Change Risk
Important
Note:You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.