Skip to content

Conversation

@jreynard-code
Copy link
Member

Several upgrades to remove current alert from dependency tracker and reduce technical debt

Upgrades:
- org.springframework.boot from 3.4.4 to 3.5.8
- org.apache.tika:tika-core from 3.2.2 to 3.2.3
- org.junit:junit-bom from 5.13.4 to 6.0.1
- com.diffplug.spotless from 7.0.3 to 8.1.0
- org.owasp.dependencycheck from 12.1.0 to 12.1.9
- com.github.jk1.dependency-license-report from 2.9 to 3.0.1
- org.jetbrains.kotlinx.kover from 0.9.1 to 0.9.3
- com.google.cloud.tools.jib from 3.4.5 to 3.5.1

Code styling:
- suppress some detekt warnings
- add trailing comas
- some indentations have changed
Upgrades:
- com.redis.om:redis-om-spring from 0.9.7 to 1.1.1
- org.springdoc:springdoc-openapi-starter-webmvc-ui from 2.8.8 to 2.8.14
- io.swagger.parser.v3:swagger-parser-v3 from 2.1.31 to 2.1.36
- org.testcontainers:postgresql from 1.20.6 to 1.21.3
- org.testcontainers:localstack from 1.20.6 to 1.21.3
- io.awspring.cloud:spring-cloud-aws-dependencies from 3.3.0 to 3.4.2
- io.awspring.cloud:spring-cloud-aws-starter-s3 from 3.3.0 to 3.4.2

Misc:
- replace BasicThreadFactory.Builder() by BasicThreadFactory.builder()
- replace InputStream.nullInputStream() in tests by " ".toByteArray() to avoid errors
- add constraint on com.redis.testcontainers:testcontainers-redis-junit to use com.redis:lettucemod:4.5.0 (compatibility)
Upgrades:
- com.fasterxml.jackson.core:jackson-annotations from 2.18.3 to 2.20
- org.springframework:spring-web from 6.2.9 to 6.2.14
- org.bouncycastle:bcpkix-jdk18on from 1.81 to 1.83
- org.springframework.boot:spring-boot-autoconfigure from 3.4.4 to 3.5.8
- org.apache.commons:commons-csv from 1.14.0 to 1.14.1
- jakarta.validation:jakarta.validation-api from 3.0.2 to 3.1.1
- org.json:json from 20240303 to 20250517
- com.fasterxml.jackson.core:jackson-databind from 2.18.3 to 2.20.1
- org.apache.commons:commons-compress from 1.27.1 to 1.28.0

Constraints:
org.springframework.boot:spring-boot-starter-undertow:
- org.jboss.xnio:xnio-api from 3.8.16.Final to 3.8.17.Final
- io.undertow:undertow-core from 2.3.18.Final to 2.3.20.Final

org.springframework.security.oauth.boot:spring-security-oauth2-autoconfigure:
- com.fasterxml.jackson.core:jackson-annotations from 2.18.3 to 2.20.1
- com.fasterxml.jackson.core:jackson-databind from 2.3.18.Final to 2.20

Removed:
- com.okta.spring:okta-spring-boot-starter

Misc:
- clean useless variables in build.gradle.kts
- set docker image version of postgres and localstack to latest for tests (integration/controller)
- Updated CycloneDX plugin version from 2.3.1 to 3.1.0 in `build.gradle.kts`.
- Replaced `CycloneDxTask` with `CyclonedxDirectTask`.
- Added `componentName` and updated output settings for BOM tasks.
- Introduced `cyclonedxDirectBom` tasks for subprojects with specific configurations.
@jreynard-code jreynard-code merged commit 336f931 into main Dec 4, 2025
80 checks passed
@jreynard-code jreynard-code deleted the upgrades_sphinx branch December 4, 2025 14:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants