Skip to content

Conversation

dafriz
Copy link
Contributor

@dafriz dafriz commented Sep 29, 2025

Bump tika to 3.2.3 from 3.2.1, jsoup to 1.21.2 from 1.21.1 resolving CVE-2025-54988

…VE-2025-54988

Signed-off-by: David Frizelle <david.frizelle@gmail.com>
@dafriz dafriz changed the title Bump tika to 3.2.3 from 3.2.1, jsoup to 1.21.2 from 1.21.1 resolving CVE-2025-54988 Bump tika to 3.2.3 from 3.2.1, jsoup to 1.21.2 from 1.21.1 Sep 29, 2025
@ilayaperumalg ilayaperumalg self-assigned this Sep 29, 2025
@ilayaperumalg ilayaperumalg added this to the 1.1.0.M3 milestone Sep 29, 2025
@ilayaperumalg
Copy link
Member

@dafriz Thanks for the PR upgrading the versions.

@ilayaperumalg ilayaperumalg merged commit 237c1bb into spring-projects:main Sep 29, 2025
2 checks passed
Willam2004 pushed a commit to Willam2004/spring-ai that referenced this pull request Oct 11, 2025
…VE-2025-54988 (spring-projects#4504)

Signed-off-by: David Frizelle <david.frizelle@gmail.com>
Signed-off-by: 家娃 <guanjing.pangj@alibaba-inc.com>
@reneleonhardt
Copy link

Why isn't it possible to use dependabot instead of waiting for contributions? 😄
If needed, only patches or security updates could be configured.

https://github.blog/changelog/2025-07-01-dependabot-supports-configuration-of-a-minimum-package-age/
https://docs.github.com/en/code-security/dependabot/working-with-dependabot/dependabot-options-reference#cooldown-

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants