Skip to content

Update tomcat, log4j2, and grpc versions to address CVEs#1334

Merged
labkey-susanh merged 2 commits intorelease26.3-SNAPSHOTfrom
26.3_fb_moreDependencyUpdates
Apr 13, 2026
Merged

Update tomcat, log4j2, and grpc versions to address CVEs#1334
labkey-susanh merged 2 commits intorelease26.3-SNAPSHOTfrom
26.3_fb_moreDependencyUpdates

Conversation

@labkey-susanh
Copy link
Copy Markdown
Contributor

@labkey-susanh labkey-susanh commented Apr 13, 2026

Rationale

New CVEs have surfaced in some of our dependencies

Update URL for oss analyzer per recommendations in this issue for the plugin to follow updates from Sonatype OSS Index to Sonatype Guide API.

Changes

  • Update tomcat version
  • Update log4j2 version
  • Update grpc version
  • Update ossIndex.url

@labkey-susanh labkey-susanh requested a review from a team April 13, 2026 17:01
@labkey-susanh labkey-susanh self-assigned this Apr 13, 2026
@labkey-susanh labkey-susanh merged commit 5213677 into release26.3-SNAPSHOT Apr 13, 2026
5 of 8 checks passed
@labkey-susanh labkey-susanh deleted the 26.3_fb_moreDependencyUpdates branch April 13, 2026 20:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants