Skip to content

Conversation

@athira1693
Copy link
Contributor

This PR updates Vert.x dependency to version 5.0.4.

As a result, it upgrades the following transitive dependencies from vulnerable versions:

Dependency Upgraded Version CVE ID
netty-codec-http2 4.2.5.Final CVE-2025-55163
Thymeleaf 3.1.2.RELEASE CVE-2023-38286

Closes: #376

Signed-off-by: Athira Sreekumar [email protected]

Copy link

@mark-VIII mark-VIII left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me. Thank you! :)

Copy link
Contributor

@neeraj-laad neeraj-laad left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@athira1693 athira1693 merged commit 06b5e49 into ibm-messaging:master Nov 18, 2025
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update Vert.x version to 5.0.4

4 participants