Skip to content

fix: Update critical security dependencies#3391

Closed
bhaskarvilles wants to merge 1 commit into
NationalSecurityAgency:integrationfrom
bhaskarvilles:fix/critical-security-updates
Closed

fix: Update critical security dependencies#3391
bhaskarvilles wants to merge 1 commit into
NationalSecurityAgency:integrationfrom
bhaskarvilles:fix/critical-security-updates

Conversation

@bhaskarvilles
Copy link
Copy Markdown

  • Update Log4j2: 2.19.0 → 2.24.3 (addresses CVE-2021-44228 and subsequent vulnerabilities)
  • Update Jackson: 2.10.0.pr1 → 2.17.2 (security fixes, using Java 11 compatible version)
  • Update Spring Framework: 5.2.2.RELEASE → 5.3.39 (latest 5.x with security patches)
  • Update Netty: 4.1.42.Final → 4.1.115.Final (security and bug fixes)
  • Update Protobuf: 3.16.3 → 3.25.5 (includes protobuf-java-util)
  • Update Commons IO: 2.6 → 2.18.0 (bug fixes and improvements)
  • Update Commons Codec: 1.12 → 1.17.1 (bug fixes)

These updates address multiple known security vulnerabilities and bring dependencies to their latest stable versions compatible with Java 11.

Breaking Changes: None expected, all updates are within compatible version ranges.
Testing: Requires full test suite validation before merge.

- Update Log4j2: 2.19.0 → 2.24.3 (addresses CVE-2021-44228 and subsequent vulnerabilities)
- Update Jackson: 2.10.0.pr1 → 2.17.2 (security fixes, using Java 11 compatible version)
- Update Spring Framework: 5.2.2.RELEASE → 5.3.39 (latest 5.x with security patches)
- Update Netty: 4.1.42.Final → 4.1.115.Final (security and bug fixes)
- Update Protobuf: 3.16.3 → 3.25.5 (includes protobuf-java-util)
- Update Commons IO: 2.6 → 2.18.0 (bug fixes and improvements)
- Update Commons Codec: 1.12 → 1.17.1 (bug fixes)

These updates address multiple known security vulnerabilities and bring
dependencies to their latest stable versions compatible with Java 11.

Breaking Changes: None expected, all updates are within compatible version ranges.
Testing: Requires full test suite validation before merge.
@billoley
Copy link
Copy Markdown
Collaborator

Duplicated changes in #3429 and added pom updates to the microservices area

@billoley billoley closed this Feb 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants