Skip to content

[WIP] Update third-party packages for CVE-2026-5588#3997

Closed
Copilot wants to merge 1 commit into
developfrom
copilot/upgrade-third-party-packages
Closed

[WIP] Update third-party packages for CVE-2026-5588#3997
Copilot wants to merge 1 commit into
developfrom
copilot/upgrade-third-party-packages

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented May 12, 2026

  • 通过语义搜索与代码检索定位与依赖版本管理相关位置(根 pom 与 BouncyCastle 依赖)
  • 在未改代码前执行基线校验(compile/package/checkstyle)并记录结果
  • 确认 CVE-2026-5588 对应的受影响三方包与当前仓库实际版本
  • 实施最小化依赖升级/修复(如需)并补充必要测试或验证
  • 运行针对性校验与最终构建校验,确保无回归
  • 完成变更说明,给出“请详细说明”所需的影响范围与结论

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4.8.2.B版本有CVE-2026-5588,能升级下相关的第3方包吗?

2 participants