Skip to content

Bump org.opensaml:opensaml-saml-impl from 4.3.2 to 5.2.2 in /auth-service#265

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/auth-service/org.opensaml-opensaml-saml-impl-5.2.1
Closed

Bump org.opensaml:opensaml-saml-impl from 4.3.2 to 5.2.2 in /auth-service#265
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/auth-service/org.opensaml-opensaml-saml-impl-5.2.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 12, 2026

Bumps org.opensaml:opensaml-saml-impl from 4.3.2 to 5.2.2.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels May 12, 2026
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

High Software Management Finding - Software License

Code library with Restrictive license

More Details

Code library com.sun.mail:jakarta.mail version 2.0.2 has GPL-2.0-with-classpath-exception license, categorized as Restrictive, its use may cause a supply chain licensing issue.

Remediation guidance

  • Review the license terms to understand its specific rules.
  • If needed, Replace this component immediately with an alternative using a permissive license (e.g., MIT, Apache 2.0).
  • Consult your legal team if the component is business-critical or the terms are unclear.

To ignore this finding as an exception, reply to this conversation with #wiz_ignore reason

If you'd like to ignore this finding in all future scans, add an exception in the .wiz file (learn more) or create an Ignore Rule (learn more).


To get more details on how to remediate this issue using AI, reply to this conversation with #wiz remediate

Bumps org.opensaml:opensaml-saml-impl from 4.3.2 to 5.2.2.

---
updated-dependencies:
- dependency-name: org.opensaml:opensaml-saml-impl
  dependency-version: 5.2.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump org.opensaml:opensaml-saml-impl from 4.3.2 to 5.2.1 in /auth-service Bump org.opensaml:opensaml-saml-impl from 4.3.2 to 5.2.2 in /auth-service May 18, 2026
@dependabot dependabot Bot force-pushed the dependabot/gradle/auth-service/org.opensaml-opensaml-saml-impl-5.2.1 branch from e68c474 to 14ddbf9 Compare May 18, 2026 07:40
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 19, 2026

Superseded by #270.

@dependabot dependabot Bot closed this May 19, 2026
@dependabot dependabot Bot deleted the dependabot/gradle/auth-service/org.opensaml-opensaml-saml-impl-5.2.1 branch May 19, 2026 02:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants