Skip to content

Reduce api CVE 4 2 2#1160

Merged
jreynard-code merged 4 commits intorelease/v4-onpremfrom
reduce_api_cve_4_2_2
Mar 30, 2026
Merged

Reduce api CVE 4 2 2#1160
jreynard-code merged 4 commits intorelease/v4-onpremfrom
reduce_api_cve_4_2_2

Conversation

@jreynard-code
Copy link
Copy Markdown
Member

No description provided.

- Upgraded `org.springframework.boot` to `3.5.5`.
- Updated and added constraints for `undertow-core` and related modules to address CVEs.
- Replaced forced dependencies for `jedis` and `lettucemod`.
- Removed outdated forced dependencies.
- Adjusted exclusions for `spring-data-redis` dependency.
…ncies

- Upgraded `org.springframework.boot` plugin to `3.5.13`.
- Removed commented-out forced dependencies and outdated CVE references for cleanup.
@jreynard-code jreynard-code requested a review from sjoubert March 30, 2026 08:18
- Updated `redisOmSpringVersion` to `0.9.11` in `build.gradle.kts`.
- Adjusted forced dependency version for `redis-om-spring` to align with the update.
…atibility

- Upgraded `actions/checkout` to `v6`, `actions/setup-java` to `v5`, and `gradle/actions/setup-gradle` to `v5`.
- Updated `aquasecurity/trivy-action` to `v0.35.0` and `github/codeql-action/upload-sarif` to `v4`.
- Enhanced artifact upload process by upgrading `actions/upload-artifact` to `v6`.
- Improved container login support with `docker/login-action` upgraded to `v3.6.0`.
@jreynard-code jreynard-code merged commit 1afe087 into release/v4-onprem Mar 30, 2026
34 checks passed
@jreynard-code jreynard-code deleted the reduce_api_cve_4_2_2 branch March 30, 2026 09:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants