Skip to content

Update io.github.openfeign:feign-bom to 13.8#1330

Merged
ryanjbaxter merged 1 commit intospring-cloud:mainfrom
maxl2287:update-feign-version
Feb 20, 2026
Merged

Update io.github.openfeign:feign-bom to 13.8#1330
ryanjbaxter merged 1 commit intospring-cloud:mainfrom
maxl2287:update-feign-version

Conversation

@maxl2287
Copy link
Contributor

@maxl2287 maxl2287 commented Feb 20, 2026

Fixes #1221
Fixes #1260

Updates to the latest release 13.8 of OpenFeign to fix the common-filupload CVE

@maxl2287 maxl2287 changed the title update io.github.openfeign:feign-bom to 13.8 Update io.github.openfeign:feign-bom to 13.8 Feb 20, 2026
Signed-off-by: Maximilian Laue <Maximilian.Laue@t-systems.com>
@maxl2287 maxl2287 force-pushed the update-feign-version branch from da73e8a to a3535d7 Compare February 20, 2026 12:53
@ryanjbaxter ryanjbaxter added dependencies Pull requests that update a dependency file and removed waiting-for-triage labels Feb 20, 2026
@ryanjbaxter ryanjbaxter added this to the 5.0.2 milestone Feb 20, 2026
@ryanjbaxter ryanjbaxter merged commit 01c0e2d into spring-cloud:main Feb 20, 2026
2 checks passed
@maxl2287 maxl2287 deleted the update-feign-version branch February 20, 2026 14:24
ryanjbaxter added a commit that referenced this pull request Feb 20, 2026
ryanjbaxter added a commit that referenced this pull request Feb 20, 2026
@ryanjbaxter ryanjbaxter removed this from the 5.0.2 milestone Feb 20, 2026
@ryanjbaxter
Copy link
Contributor

I just realized that this was not a patch release of Feign, we cannot upgrade to this version because it is considered a breaking change

@ryanjbaxter
Copy link
Contributor

Feign released 13.6.1. I gave upgraded to that version in 5828a8e

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

3 participants