Skip to content

[Snyk] Security upgrade tomcat from 9.0.113-jre11-temurin to 9.0.115-jre11-temurin#1498

Merged
wajda merged 1 commit intodevelopfrom
snyk-fix-07242f8a4c0823c766cbe13d12b8e718
Feb 13, 2026
Merged

[Snyk] Security upgrade tomcat from 9.0.113-jre11-temurin to 9.0.115-jre11-temurin#1498
wajda merged 1 commit intodevelopfrom
snyk-fix-07242f8a4c0823c766cbe13d12b8e718

Conversation

@wajda
Copy link
Contributor

@wajda wajda commented Feb 10, 2026

snyk-top-banner

Snyk has created this PR to fix 4 vulnerabilities in the dockerfile dependencies of this project.

Keeping your Docker base image up-to-date means you’ll benefit from security fixes in the latest version of your chosen image.

Snyk changed the following file(s):

  • kafka-gateway/Dockerfile

We recommend upgrading to tomcat:9.0.115-jre11-temurin, as this image has only 18 known vulnerabilities. To do this, merge this pull request, then verify your application still works as expected.

Vulnerabilities that will be fixed with an upgrade:

Issue Score
medium severity CVE-2025-15467
SNYK-UBUNTU2404-OPENSSL-15121120
  586  
medium severity CVE-2025-15467
SNYK-UBUNTU2404-OPENSSL-15121120
  586  
low severity CVE-2025-69421
SNYK-UBUNTU2404-OPENSSL-15120902
  436  
low severity CVE-2025-69419
SNYK-UBUNTU2404-OPENSSL-15120929
  436  
low severity CVE-2026-22796
SNYK-UBUNTU2404-OPENSSL-15120958
  436  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Learn about vulnerability in an interactive lesson of Snyk Learn.

@wajda wajda requested a review from cerveada as a code owner February 10, 2026 13:06
@sonarqubecloud
Copy link

@wajda
Copy link
Contributor Author

wajda commented Feb 10, 2026

Snyk checks have passed. No issues have been found so far.

Status Scanner Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@coderabbitai
Copy link

coderabbitai bot commented Feb 10, 2026

Important

Review skipped

Ignore keyword(s) in the title.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch snyk-fix-07242f8a4c0823c766cbe13d12b8e718

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions
Copy link

JaCoCo code coverage report

There is no coverage information present for the Files changed

Total Project Coverage 33.35% 🍏

@wajda wajda merged commit eccf11f into develop Feb 13, 2026
8 checks passed
@wajda wajda deleted the snyk-fix-07242f8a4c0823c766cbe13d12b8e718 branch February 13, 2026 13:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants