Skip to content

Conversation

@pboos
Copy link
Contributor

@pboos pboos commented Nov 3, 2025

Summary

This PR addresses the security vulnerabilities reported by Dependabot for the Apache Tomcat embedded core library by upgrading the version from 11.0.10 to 11.0.12 in the build.gradle file.

Details

  • Updated ext['tomcat.version'] from 11.0.10 to 11.0.12.
  • Adjusted the implementation version of tomcat-embed-core to 11.0.13 with updated security vulnerability notes.

JIRA Ticket

This change resolves the security alert described in JIRA ticket CHK-12769, which highlights the need to update the vulnerable Apache Tomcat dependency to mitigate security risks.


@pboos pboos requested a review from a team as a code owner November 3, 2025 08:07
@pboos pboos requested a review from juliocastrodev November 3, 2025 08:07
@pboos pboos merged commit 894baf1 into main Nov 3, 2025
4 checks passed
@pboos pboos deleted the CHK-12769-dependabot-security-alert branch November 3, 2025 08:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants