File tree Expand file tree Collapse file tree 4 files changed +11
-10
lines changed Expand file tree Collapse file tree 4 files changed +11
-10
lines changed Original file line number Diff line number Diff line change 22
33
44# BACKEND
5+ gradle /libs.versions.toml @ kafbat/backend
56/build.gradle @ kafbat/backend
67/gradle.properties @ kafbat/backend
78/settings.gradle @ kafbat/backend
Original file line number Diff line number Diff line change 77 interval : weekly
88 time : " 10:00"
99 timezone : Europe/London
10- reviewers :
11- - " kafbat/backend"
1210 open-pull-requests-limit : 10
1311 labels :
1412 - " type/dependencies"
@@ -27,8 +25,6 @@ updates:
2725 interval : weekly
2826 time : " 10:00"
2927 timezone : Europe/London
30- reviewers :
31- - " kafbat/backend"
3228 open-pull-requests-limit : 10
3329 ignore :
3430 - dependency-name : " azul/zulu-openjdk-alpine"
@@ -43,8 +39,6 @@ updates:
4339 interval : weekly
4440 time : " 10:00"
4541 timezone : Europe/London
46- reviewers :
47- - " kafbat/frontend"
4842 open-pull-requests-limit : 10
4943 versioning-strategy : increase-if-necessary
5044 labels :
@@ -64,8 +58,6 @@ updates:
6458 interval : weekly
6559 time : " 10:00"
6660 timezone : Europe/London
67- reviewers :
68- - " kafbat/devops"
6961 open-pull-requests-limit : 10
7062 labels :
7163 - " type/dependencies"
Original file line number Diff line number Diff line change @@ -14,7 +14,12 @@ dependencies {
1414 implementation project(" :contract" )
1515 implementation project(" :serde-api" )
1616 implementation libs. spring. starter. webflux
17- implementation libs. spring. starter. security
17+ implementation(libs. spring. starter. security){
18+ exclude group : ' com.nimbusds' , module : ' nimbus-jose-jwt' because(" Temporary overwrite to fix CVE-2025-53864. See https://avd.aquasec.com/nvd/2025/cve-2025-53864/" )
19+ }
20+ implementation(libs. nimbus. jose. jwt){
21+ because(" Fixes CVE-2025-5386. See https://avd.aquasec.com/nvd/2025/cve-2025-53864/" )
22+ }
1823 implementation libs. spring. starter. actuator
1924 implementation libs. spring. starter. logging
2025 implementation libs. spring. starter. oauth2. client
Original file line number Diff line number Diff line change 11[versions ]
22spring-boot = ' 3.5.3'
3+ nimbus-jose-jwt = ' 10.0.2'
34
45aws-msk-auth = ' 2.3.0'
56azure-identity = ' 1.15.4'
67
7- apache-commons-lang3 = ' 3.12 .0'
8+ apache-commons-lang3 = ' 3.18 .0'
89apache-commons-io = ' 2.18.0'
910apache-commons-pool2 = ' 2.12.1'
1011apache-datasketches = ' 3.1.0'
@@ -60,6 +61,8 @@ spring-starter-actuator = { module = 'org.springframework.boot:spring-boot-start
6061spring-starter-test = { module = ' org.springframework.boot:spring-boot-starter-test' , version.ref = ' spring-boot' }
6162spring-starter-webflux = { module = ' org.springframework.boot:spring-boot-starter-webflux' , version.ref = ' spring-boot' }
6263spring-starter-security = { module = ' org.springframework.boot:spring-boot-starter-security' , version.ref = ' spring-boot' }
64+ # Temporary overwrite to fix CVE-2025-53864
65+ nimbus-jose-jwt = { module = ' com.nimbusds:nimbus-jose-jwt' , version.ref = ' nimbus-jose-jwt' }
6366spring-starter-validation = { module = ' org.springframework.boot:spring-boot-starter-validation' , version.ref = ' spring-boot' }
6467spring-starter-oauth2-client = { module = ' org.springframework.boot:spring-boot-starter-oauth2-client' , version.ref = ' spring-boot' }
6568spring-starter-logging = { module = ' org.springframework.boot:spring-boot-starter-logging' , version.ref = ' spring-boot' }
You can’t perform that action at this time.
0 commit comments