Change 29210

Paul Allen
[SECURITY] Use HTTPS to resolve dependencies in Maven Build

vuln-fix: Use HTTPS instead of HTTP to resolve deps CVE-2021-26291
This fixes a security vulnerability in this project where the `pom.xml`
files were configuring Maven to resolve dependencies over HTTP instead of

Weakness: CWE-829: Inclusion of Functionality from Untrusted Control Sphere
Severity: High
CVSSS: 8.1
Detection: CodeQL & OpenRewrite (

Reported-by: Jonathan Leitschuh <>
Signed-off-by: Jonathan Leitschuh <>

Bug-tracker: JLLeitschuh/security-research#8

Co-authored-by: Moderne <>
1 edited 0 added 0 deleted
Tip: Use n and p to cycle through the changes.