Skip to content

Commit 3cbd794

Browse files
rpanackalnewtork
andauthored
fix: [DevOps] Upgrading spring springframework and spring boot versions to remove vulnerabilities (#467)
* Upgrading spring springframework version to one without vulnerability * Upgrading spring boot * declare tomcat version * Update sample-code/spring-app/pom.xml --------- Co-authored-by: Roshin Rajan Panackal <[email protected]> Co-authored-by: Alexander Dümont <[email protected]>
1 parent 1297536 commit 3cbd794

File tree

2 files changed

+13
-2
lines changed

2 files changed

+13
-2
lines changed

pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -66,7 +66,7 @@
6666
<checkstyle.version>10.25.0</checkstyle.version>
6767
<system-stubs.version>2.1.3</system-stubs.version>
6868
<surefire.version>3.5.3</surefire.version>
69-
<springframework.version>6.2.1</springframework.version>
69+
<springframework.version>6.2.8</springframework.version>
7070
<spring-ai.version>1.0.0-M6</spring-ai.version>
7171
<reactor-core.version>3.6.12</reactor-core.version>
7272
<dotenv-java.version>3.2.0</dotenv-java.version>

sample-code/spring-app/pom.xml

Lines changed: 12 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@
3333
</developers>
3434
<properties>
3535
<project.rootdir>${project.basedir}/../../</project.rootdir>
36-
<spring-boot.version>3.4.5</spring-boot.version>
36+
<spring-boot.version>3.5.0</spring-boot.version>
3737
<logback.version>1.5.18</logback.version>
3838
<cf-logging.version>3.8.5</cf-logging.version>
3939
<!-- Skip end-to-end tests by default, can be overridden with -DskipTests=false -->
@@ -44,6 +44,17 @@
4444
<enforcer.skipEnforceSpringAIOptional>true</enforcer.skipEnforceSpringAIOptional>
4545
</properties>
4646

47+
<dependencyManagement>
48+
<!-- Temporary fix for CVE-2025-48988 -->
49+
<dependencies>
50+
<dependency>
51+
<groupId>org.apache.tomcat.embed</groupId>
52+
<artifactId>tomcat-embed-core</artifactId>
53+
<version>10.1.42</version>
54+
</dependency>
55+
</dependencies>
56+
</dependencyManagement>
57+
4758
<dependencies>
4859
<!-- scope "compile" -->
4960
<dependency>

0 commit comments

Comments
 (0)