Skip to content

Bump dependency versions to address OWASP CVE findings. - #211

Open
muratugureminoglu wants to merge 5 commits into
masterfrom
fix/owasp-workflow-reliability
Open

Bump dependency versions to address OWASP CVE findings.#211
muratugureminoglu wants to merge 5 commits into
masterfrom
fix/owasp-workflow-reliability

Conversation

@muratugureminoglu

Copy link
Copy Markdown
Contributor

No description provided.

Upgrade Spring, Tomcat, Jackson, and MINA to patched releases that fix reported security vulnerabilities in the OWASP workflow scan.

Co-authored-by: Cursor <cursoragent@cursor.com>
@muratugureminoglu
muratugureminoglu force-pushed the fix/owasp-workflow-reliability branch from f6e317f to 8ec6930 Compare July 27, 2026 09:12
muratugureminoglu and others added 4 commits July 27, 2026 15:25
Override Spring Boot's default Kotlin 1.9.25 so okhttp and other transitive dependencies resolve to a current stdlib release.

Co-authored-by: Cursor <cursoragent@cursor.com>
Import spring-framework-bom 6.2.19 and pin Tomcat artifacts to 10.1.57 so transitive dependencies no longer resolve to Boot's older managed versions.

Co-authored-by: Cursor <cursoragent@cursor.com>
Import jackson-bom after spring-boot-dependencies so transitive Jackson artifacts align to the patched 2.18.x line instead of Boot's default 2.21.2.

Co-authored-by: Cursor <cursoragent@cursor.com>
Import Jackson, Kotlin and Spring Framework BOMs before spring-boot-dependencies and explicitly pin spring-aop and kotlin-stdlib so Maven resolves patched versions instead of Boot defaults.

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant