Move to Gradle v7.6.3 for all wrappers.#317
Merged
bestbeforetoday merged 1 commit intohyperledger:mainfrom Oct 20, 2023
benjsmi:newer-gradle
Merged
Move to Gradle v7.6.3 for all wrappers.#317bestbeforetoday merged 1 commit intohyperledger:mainfrom benjsmi:newer-gradle
bestbeforetoday merged 1 commit intohyperledger:mainfrom
benjsmi:newer-gradle
Conversation
Contributor
Author
|
Merged in other merged PR for org.json to this PR to avoid conflicts. |
Contributor
Author
|
@bestbeforetoday -- do you mind reviewing this? |
Contributor
Author
|
@bestbeforetoday Read up on the right way to upgrade Gradle Wrapper and have applied those changes to this PR now. Thanks for the tip! |
Member
bestbeforetoday
left a comment
There was a problem hiding this comment.
It looks like you might have missed the Gradle wrapper upgrade in the examples/fabric-contract-example-gradle-kotlin directory. Also the commits all need a signoff statement (git commit --amend --signoff)
Signed-off-by: Ben Smith <benjsmi@us.ibm.com>
|
Kudos, SonarCloud Quality Gate passed! |
Contributor
Author
|
@bestbeforetoday yeah I definitely ran the Oddly enough, the JAR file in that directory does not/did not seem to need changing. Not sure why that is. |
bestbeforetoday
approved these changes
Oct 20, 2023
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.








As per https://nvd.nist.gov/vuln/detail/CVE-2023-44387, Gradle v7.6.2 is vulnerable. Moves all incorporate wrappers to the latest version of Gradle in their properties spec such that they use the latest Gradle (on the 7.6.x branch) to run the build.
Related to #312 but not mentioned explicitly in that issue.