Commit 3c1ab8c3 authored by Ankur Verma's avatar Ankur Verma
Browse files

security: upgrade Spring Boot, Tomcat, Bouncy Castle and related deps to address CVEs

Bumped runtime/dependency versions in the bundled WARs across all Java
toolchains. No application code changes.

Component         | Old      | New
------------------+----------+------------------
Spring Boot       | 3.4.5    | 3.5.12
Spring Framework  | 6.2.11   | 6.2.17
Apache Tomcat     | 11.0.10  | 11.0.21
Bouncy Castle     | 1.79     | 1.84
Logback           | -        | 1.5.25 (pinned)
Jackson BOM       | -        | 2.18.6 (pinned)

Addresses known CVEs including Spring Boot Actuator vulnerabilities.

Co-Authored-By: default avatarClaude Opus 4.7 (1M context) <noreply@anthropic.com>
parent bcbe3210
Loading
Loading
Loading
Loading
+648 KiB (36.4 MiB)

File changed.

No diff preview for this file type.

+648 KiB (36.4 MiB)

File changed.

No diff preview for this file type.

+648 KiB (36.4 MiB)

File changed.

No diff preview for this file type.