Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump com.graphql-java:graphql-java from 18.2 to 18.3 #2245

Closed
wants to merge 1 commit into from

Conversation

yeikel
Copy link
Contributor

@yeikel yeikel commented Jul 28, 2022

This is a security bugfix release containing only one PR: graphql-java/graphql-java#2897

GraphQL Java has a max token limit per request preventing DOS attacks. But in some circumstances it was not enough to prevent malicious requests. This release fixes this problem.

All details can be found here: graphql-java/graphql-java#2892

Eventually we should merge #2244 but it seems that we need to do some work as there are broken tests

See https://github.com/graphql-java/graphql-java/releases/tag/v18.3

@yeikel yeikel force-pushed the graphql/18.3 branch 2 times, most recently from 89ed1f5 to da06817 Compare July 28, 2022 01:03
@yeikel yeikel changed the title Graphql/18.3 Bump com.graphql-java:graphql-java from 18.2 to 18.3 Jul 28, 2022
@yeikel yeikel marked this pull request as ready for review July 28, 2022 01:05
@yeikel
Copy link
Contributor Author

yeikel commented Jul 28, 2022

@tsegismont Can you please take a look at this one?

The failures seem unrelated to this change

As #2244 is ready to go as well, this is probably not needed

@yeikel
Copy link
Contributor Author

yeikel commented Jul 28, 2022

Closing. I think that we should go with #2244 instead

@yeikel yeikel closed this Jul 28, 2022
@yeikel yeikel deleted the graphql/18.3 branch July 28, 2022 13:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant