fix: Upgrade Tika-Core to 3.2.2 (ATT-64) - #83
Open
ashuverma25 wants to merge 2 commits into
Open
Conversation
…ibility (resolves ATT-64)
|
Hey @ashuverma25 ! Thanks for jumping in to help fix this CVE! I've been looking into this issue as well, and while reviewing, I noticed a couple of things that might block this from getting merged as-is on the 4.x line:
Given the Java 11 requirement, Ian Bacher mentioned in the Slack thread that the best path forward is to create a new 5.x major version branch explicitly targeting Java 11+, rather than trying to force it into 4.x. I've just opened a PR to handle the 5.x major version bump alongside this Tika patch if you'd like to collaborate or take a look at the approach there! |
…, and fix module context XML
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



This PR addresses the security vulnerability in ATT-64 by upgrading tika-core from 2.9.2 to 3.2.2.
Changes made:
Updated pom.xml dependency version.
Migrated AttachmentsContextTest.java from deprecated org.mockito.Matchers to org.mockito.ArgumentMatchers to resolve breaking changes.
Cleaned up legacy @verifies annotations to ensure build compatibility.
Verification:
Successfully built locally using mvn clean install (Build Success).
Closes ATT-64