-
Notifications
You must be signed in to change notification settings - Fork 814
Closed
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency file
Milestone
Description
By using Spring boot 3.4.2 and Spring Cloud (2024.0.0) one of its dependencies is Apache Commons IO (2.11.0). Any schedule to update to its lates considering that 2.11.0 version got a CVE (https://mvnrepository.com/artifact/commons-io/commons-io/2.11.0)?
More details:
GHSA-78wr-2p64-hpwj
Thanks in advance.
Zernov-A and tr4l
Metadata
Metadata
Assignees
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency file