jmx_exporter 0.16.1 is available

7 views
Skip to first unread message

Fabian Stäber

unread,
Jul 13, 2021, 6:54:12 PM7/13/21
to prometheus-announce

Hello,

I just released a minor updated to the jmx_exporter (https://github.com/prometheus/jmx_exporter/releases/tag/parent-0.16.1).

It fixes a false positive CVE warning. The Java 7+ binary of the previous release contains metadata pointing to the snakeyaml library version 1.23. This causes the Trivy security scanner to wrongly report CVE-2017-18640, even though that snakeyaml version is not included in the binary.

Update 0.16.1 removes the misleading metadata.

Fabian
Reply all
Reply to author
Forward
0 new messages