Skip to content

Conversation

@trask
Copy link
Member

@trask trask commented Feb 7, 2025

OSSF scorecard is dinging us for vulnerabilities in the old spring version (it appears to only look at pom file dependencies)

<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-starter-parent</artifactId>
<version>2.6.1</version>
<version>3.4.1</version>
Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

one version below latest to test that the ignorePresets above will keep us updated going forward

@trask trask merged commit d0b12d8 into open-telemetry:main Feb 7, 2025
18 checks passed
@trask trask deleted the update-test-dependencies branch February 7, 2025 18:35
breedx-splk pushed a commit to breedx-splk/opentelemetry-java-contrib that referenced this pull request Feb 14, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants