Skip to content

Replace dependency mysql:mysql-connector-java with com.mysql:mysql-connector-j#275

Open
dev-mend-for-github-com[bot] wants to merge 1 commit intovp-remfrom
whitesource-remediate/mysql-mysql-connector-java-replacement
Open

Replace dependency mysql:mysql-connector-java with com.mysql:mysql-connector-j#275
dev-mend-for-github-com[bot] wants to merge 1 commit intovp-remfrom
whitesource-remediate/mysql-mysql-connector-java-replacement

Conversation

@dev-mend-for-github-com
Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change
mysql:mysql-connector-java → com.mysql:mysql-connector-j compile replacement 5.1.358.0.33

By merging this PR, the below issues will be automatically resolved and closed:

Severity CVSS Score Vulnerability Reachability GitHub Issue
High 8.8 CVE-2018-3258 #222
High 8.5 CVE-2017-3523 #37
Medium 6.4 CVE-2017-3586 #146
Medium 6.3 CVE-2019-2692 #38
Medium 5.0 CVE-2020-2934 #131
Medium 4.7 CVE-2020-2875 #97
Low 3.3 CVE-2017-3589 #142
Low 2.2 CVE-2020-2933 #126

This is a special PR that replaces mysql:mysql-connector-java with the community suggested minimal stable replacement version.


  • If you want to rebase/retry this PR, check this box

@dev-mend-for-github-com dev-mend-for-github-com bot added the security fix Security fix generated by Mend label Mar 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants