Hi Gunnar,
I have upgraded the embedded and remote host JDK to the latest version of Azul Zulu 11 in these commits:
Unfortunately, it was one day after the baseline for 2.2.0 was picked, so it will only be part of Bazel 3.0, which will hopefully be released very soon now.
If you want to build your own Bazel release with the newer embedded JDK, it should be enough to just cherry-pick that commit and rebuild it. You can verify the JDK version afterwards via "bazel info".
Could you share some more information about the security vulnerability that affects Bazel? We might want to create patch releases for older versions then.
Cheers,
Philipp
Philipp Wollermann | Software Engineer |
phi...@google.comGoogle Germany GmbH | Erika-Mann-Straße 33 | 80636 München
Geschäftsführer: Paul Manicle, Halimah DeLaine Prado
Registergericht und -nummer: Hamburg, HRB 86891
Sitz der Gesellschaft: Hamburg