mirror of
				https://github.com/dromara/RuoYi-Vue-Plus.git
				synced 2025-11-04 16:23:42 +08:00 
			
		
		
		
	fix 修复 snakeyaml 漏洞 强制升级依赖版本(临时处理等boot升级)
This commit is contained in:
		
							
								
								
									
										9
									
								
								pom.xml
									
									
									
									
									
								
							
							
						
						
									
										9
									
								
								pom.xml
									
									
									
									
									
								
							@@ -40,6 +40,8 @@
 | 
			
		||||
 | 
			
		||||
        <!-- 统一 guava 版本 解决隐式漏洞问题 -->
 | 
			
		||||
        <guava.version>31.1-jre</guava.version>
 | 
			
		||||
        <!-- 临时修复 snakeyaml 漏洞 -->
 | 
			
		||||
        <snakeyaml.version>1.31</snakeyaml.version>
 | 
			
		||||
 | 
			
		||||
        <!-- OSS 配置 -->
 | 
			
		||||
        <aws-java-sdk-s3.version>1.12.300</aws-java-sdk-s3.version>
 | 
			
		||||
@@ -254,6 +256,13 @@
 | 
			
		||||
                <version>${guava.version}</version>
 | 
			
		||||
            </dependency>
 | 
			
		||||
 | 
			
		||||
            <!-- 临时修复 snakeyaml 漏洞 -->
 | 
			
		||||
            <dependency>
 | 
			
		||||
                <groupId>org.yaml</groupId>
 | 
			
		||||
                <artifactId>snakeyaml</artifactId>
 | 
			
		||||
                <version>${snakeyaml.version}</version>
 | 
			
		||||
            </dependency>
 | 
			
		||||
 | 
			
		||||
            <!-- 定时任务 -->
 | 
			
		||||
            <dependency>
 | 
			
		||||
                <groupId>com.ruoyi</groupId>
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user