Skip to content

Conversation

@labkey-tchad
Copy link
Member

Rationale

Only 5.3.0 - 5.3.41 are affected by this CVE: https://spring.io/security/cve-2024-38828
Suppressing rather than bumping springVersion to be out of sync with springBootVersion.

Related Pull Requests

  • N/A

Changes

  • Suppress CVE false-positive for spring-web 6.1.14

@labkey-tchad labkey-tchad merged commit aec0270 into release24.11-SNAPSHOT Nov 19, 2024
3 of 6 checks passed
@labkey-tchad labkey-tchad deleted the 24.11_fb_springUpdate branch November 19, 2024 00:40
labkey-susanh pushed a commit that referenced this pull request Dec 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants