Skip to content

chore(deps): bump okhttp-eventsource#374

Merged
gastonfournier merged 1 commit intoUnleash:mainfrom
igor-tink:okhttp-eventsource-bump
Apr 17, 2026
Merged

chore(deps): bump okhttp-eventsource#374
gastonfournier merged 1 commit intoUnleash:mainfrom
igor-tink:okhttp-eventsource-bump

Conversation

@igor-tink
Copy link
Copy Markdown
Contributor

@igor-tink igor-tink commented Apr 14, 2026

The old version relies on okhttp v 4.9.3 which is marked as security issue in Sonatype. 4.3.0 relies on the same version as already defined in the pom.xml - 4.12.0

Reported issues are located in:

  • com.squareup.okio : okio : 2.8.0
  • org.jetbrains.kotlin : kotlin-stdlib : 1.4.10
Screenshot 2026-04-14 at 08 48 11 Screenshot 2026-04-14 at 08 47 57

Fixes: #375

Copy link
Copy Markdown
Contributor

@gastonfournier gastonfournier left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @igor-tink! I looked at the release notes, and it seems it's only the version upgrade plus some improvements in their release processes.

@github-project-automation github-project-automation Bot moved this from Investigating to Approved PRs in Issues and PRs Apr 17, 2026
@gastonfournier gastonfournier merged commit a725973 into Unleash:main Apr 17, 2026
11 checks passed
@github-project-automation github-project-automation Bot moved this from Approved PRs to Done in Issues and PRs Apr 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

launchdarkly eventsource-okhttp dependency needs an upgrade due to okio CVE

3 participants