Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: Upgrades springboot to 3.2.5 #3408

Merged
merged 1 commit into from Apr 24, 2024
Merged

fix: Upgrades springboot to 3.2.5 #3408

merged 1 commit into from Apr 24, 2024

Conversation

phantomjinx
Copy link
Member

  • The CVE requires the upgrade of spring products to 6.1.6+. To achieve this upgrade both the spring version and the springboot version in the pom configuration.

  • See CVE described by https://spring.io/security/cve-2024-22262

* The CVE requires the upgrade of spring products to 6.1.6+. To achieve
  this upgrade both the spring version and the springboot version in the
  pom configuration.

* See CVE described by https://spring.io/security/cve-2024-22262
Copy link
Member

@tadayosi tadayosi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note that we cannot yet upgrade 4.x-redhat branch until CSB is upgraded to a version that supports those SB versions.

Copy link

Test Results

  4 files  ±0    4 suites  ±0   14m 29s ⏱️ +4s
 66 tests ±0   65 ✅ ±0   1 💤 ±0  0 ❌ ±0 
268 runs  ±0  258 ✅ ±0  10 💤 ±0  0 ❌ ±0 

Results for commit a1d0d5f. ± Comparison against base commit 961ebe1.

@hawtio-ci
Copy link

hawtio-ci bot commented Apr 24, 2024

Test results

Run attempt: 1468
Detailed summary

NAME TESTS PASSED ✅ SKIPPED 💤 FAILED ❌ ERRORS 🚫 TIME 🕖
results-quarkus-17-firefox 67 65 2 0 0 207.903
results-quarkus-21-firefox 67 65 2 0 0 226.04
results-springboot-17-firefox 67 64 3 0 0 219.591
results-springboot-21-firefox 67 64 3 0 0 216.042

@phantomjinx phantomjinx changed the title fix: Upgrades springboot to 3.2.5 for CVE-2024-22262 fix: Upgrades springboot to 3.2.5 Apr 24, 2024
@phantomjinx phantomjinx merged commit f6d9287 into hawtio:4.x Apr 24, 2024
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants