Skip to content

Conversation

shub-est
Copy link

@shub-est shub-est commented Oct 6, 2025

Summary

Why

To remove the CVEs as outlined below:

Netty
CVE-2025-55163
CVE-2025-58056
CVE-2025-58057

Jetty
CVE-2025-5115

Spring6
CVE-2024-38820
CVE-2025-22233
CVE-2025-41234
CVE-2025-41249

What

Upgrade the dependency versions

Netty - 4.1.122.Final -> 4.1.125.Final
Jetty - 12.0.22 -> 12.0.27
Spring6 - 6.0.23 -> 6.2.11

Evidence

trivy_output.json

Additional Resources

I was fixing the Jettison CVEs and there is a test case which is failing. I have raised a question about the same. This would be raised as a separate PR post the discussion.
#6005

@shub-est shub-est marked this pull request as draft October 6, 2025 10:59
@shub-est shub-est marked this pull request as ready for review October 6, 2025 11:00
@shub-est
Copy link
Author

shub-est commented Oct 8, 2025

Closing in favour of #6009

@shub-est shub-est closed this Oct 8, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant