Skip to content

Updated tomcat-el version reducing vulnerabilities list#873

Merged
kwin merged 1 commit into
Netcentric:developfrom
Amoratinos:update-tomcat-dependency
Apr 29, 2026
Merged

Updated tomcat-el version reducing vulnerabilities list#873
kwin merged 1 commit into
Netcentric:developfrom
Amoratinos:update-tomcat-dependency

Conversation

@Amoratinos
Copy link
Copy Markdown
Contributor

@Amoratinos Amoratinos commented Apr 29, 2026

Closes #874

Updating tomcat-el minor version to reduce the number of CVEs associated to that library version.

org.apache.tomcat:tomcat-el-api @ 10.1.52

org.apache.tomcat:tomcat-el-api @ 10.1.54

@kwin kwin merged commit 41b1945 into Netcentric:develop Apr 29, 2026
11 of 12 checks passed
@kwin
Copy link
Copy Markdown
Member

kwin commented May 6, 2026

Just FTR: AFAICS none of the vulnerabilities affected the used EL functionality from Tomcat so I consider all warning related to it false positives, but upgrading does not do harm either.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Upgrade tomcat-jasper-el and tomcat-el-api to latest 10.1 minor version

2 participants