Skip to content

Commit 5d8c228

Browse files
authored
Merge branch 'main' into fix/broder-settings
2 parents a7460eb + a8a5eac commit 5d8c228

File tree

4 files changed

+11
-10
lines changed

4 files changed

+11
-10
lines changed

.github/CODEOWNERS

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22

33

44
# BACKEND
5+
gradle/libs.versions.toml @kafbat/backend
56
/build.gradle @kafbat/backend
67
/gradle.properties @kafbat/backend
78
/settings.gradle @kafbat/backend

.github/dependabot.yml

Lines changed: 0 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -7,8 +7,6 @@ updates:
77
interval: weekly
88
time: "10:00"
99
timezone: Europe/London
10-
reviewers:
11-
- "kafbat/backend"
1210
open-pull-requests-limit: 10
1311
labels:
1412
- "type/dependencies"
@@ -27,8 +25,6 @@ updates:
2725
interval: weekly
2826
time: "10:00"
2927
timezone: Europe/London
30-
reviewers:
31-
- "kafbat/backend"
3228
open-pull-requests-limit: 10
3329
ignore:
3430
- dependency-name: "azul/zulu-openjdk-alpine"
@@ -43,8 +39,6 @@ updates:
4339
interval: weekly
4440
time: "10:00"
4541
timezone: Europe/London
46-
reviewers:
47-
- "kafbat/frontend"
4842
open-pull-requests-limit: 10
4943
versioning-strategy: increase-if-necessary
5044
labels:
@@ -64,8 +58,6 @@ updates:
6458
interval: weekly
6559
time: "10:00"
6660
timezone: Europe/London
67-
reviewers:
68-
- "kafbat/devops"
6961
open-pull-requests-limit: 10
7062
labels:
7163
- "type/dependencies"

api/build.gradle

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,12 @@ dependencies {
1414
implementation project(":contract")
1515
implementation project(":serde-api")
1616
implementation libs.spring.starter.webflux
17-
implementation libs.spring.starter.security
17+
implementation(libs.spring.starter.security){
18+
exclude group: 'com.nimbusds', module: 'nimbus-jose-jwt' because("Temporary overwrite to fix CVE-2025-53864. See https://avd.aquasec.com/nvd/2025/cve-2025-53864/")
19+
}
20+
implementation(libs.nimbus.jose.jwt){
21+
because("Fixes CVE-2025-5386. See https://avd.aquasec.com/nvd/2025/cve-2025-53864/")
22+
}
1823
implementation libs.spring.starter.actuator
1924
implementation libs.spring.starter.logging
2025
implementation libs.spring.starter.oauth2.client

gradle/libs.versions.toml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,11 @@
11
[versions]
22
spring-boot = '3.5.3'
3+
nimbus-jose-jwt = '10.0.2'
34

45
aws-msk-auth = '2.3.0'
56
azure-identity = '1.15.4'
67

7-
apache-commons-lang3 = '3.12.0'
8+
apache-commons-lang3 = '3.18.0'
89
apache-commons-io = '2.18.0'
910
apache-commons-pool2 = '2.12.1'
1011
apache-datasketches = '3.1.0'
@@ -60,6 +61,8 @@ spring-starter-actuator = { module = 'org.springframework.boot:spring-boot-start
6061
spring-starter-test = { module = 'org.springframework.boot:spring-boot-starter-test', version.ref = 'spring-boot' }
6162
spring-starter-webflux = { module = 'org.springframework.boot:spring-boot-starter-webflux', version.ref = 'spring-boot' }
6263
spring-starter-security = { module = 'org.springframework.boot:spring-boot-starter-security', version.ref = 'spring-boot' }
64+
# Temporary overwrite to fix CVE-2025-53864
65+
nimbus-jose-jwt = { module = 'com.nimbusds:nimbus-jose-jwt', version.ref = 'nimbus-jose-jwt' }
6366
spring-starter-validation = { module = 'org.springframework.boot:spring-boot-starter-validation', version.ref = 'spring-boot' }
6467
spring-starter-oauth2-client = { module = 'org.springframework.boot:spring-boot-starter-oauth2-client', version.ref = 'spring-boot' }
6568
spring-starter-logging = { module = 'org.springframework.boot:spring-boot-starter-logging', version.ref = 'spring-boot' }

0 commit comments

Comments
 (0)