Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade Spring Boot Starter Web to 2.7.12 #97

Merged
merged 6 commits into from
Jul 28, 2023

Conversation

andytinkham
Copy link
Contributor

Desired Outcome

Remove versions of Spring Framework vulnerable to CVE-2023-20863 (deemed low risk for the conjur spring boot sdk).

Implemented Changes

Upgraded spring-boot-starter-web to 2.7.12 (latest version in 2.7.x line. Migration to 3.x will be ticketed separately).
Upgrade junit to 5.9.3 (no security impact).

Signed-off-by: Andy Tinkham <andy.tinkham@cyberark.com>
Signed-off-by: Andy Tinkham <andy.tinkham@cyberark.com>
andytinkham and others added 2 commits June 23, 2023 16:42
Signed-off-by: Andy Tinkham <andy.tinkham@cyberark.com>
@itsbrugu itsbrugu requested a review from a team as a code owner July 5, 2023 16:39
itsbrugu
itsbrugu previously approved these changes Jul 28, 2023
@itsbrugu itsbrugu merged commit 1e912d2 into master Jul 28, 2023
@itsbrugu itsbrugu deleted the update-spring-boot-2.7.12 branch July 28, 2023 15:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

2 participants