Skip to content

fix: patch backend dependency vulnerabilities#28

Merged
tsekovTriesCoding merged 1 commit intomainfrom
fix/backend-dependency-vulnerabilities
Mar 18, 2026
Merged

fix: patch backend dependency vulnerabilities#28
tsekovTriesCoding merged 1 commit intomainfrom
fix/backend-dependency-vulnerabilities

Conversation

@tsekovTriesCoding
Copy link
Owner

  • Bump Spring Boot 4.0.2 -> 4.0.3 (fixes Jackson, Tomcat, AssertJ transitives)
  • Bump Spring Cloud 2025.1.0 -> 2025.1.1 (fixes Eureka/httpclient transitives)
  • Bump MySQL Connector/J 8.3.0 -> 8.4.0
  • Bump Testcontainers 2.0.0 -> 2.0.3
  • Bump springdoc 2.8.6 -> 3.0.2 (Spring Boot 4 compatible line)
  • Bump JJWT 0.12.6 -> 0.12.7, centralized in parent POM
  • Bump Cloudinary 2.0.0 -> 2.3.2, centralized in parent POM
  • Override Jackson BOMs 2.20.2 -> 2.21.1 / 3.0.4 -> 3.1.0 (CVE-2026-29062)
  • Override Kafka 4.1.1 -> 4.1.2 (CVE-2025-48734)
  • Override lz4-java -> 1.8.1, protobuf-java -> 4.34.0 (transitive CVE fixes)
  • Update README badges and tech stack versions

- Bump Spring Boot 4.0.2 -> 4.0.3 (fixes Jackson, Tomcat, AssertJ transitives)
- Bump Spring Cloud 2025.1.0 -> 2025.1.1 (fixes Eureka/httpclient transitives)
- Bump MySQL Connector/J 8.3.0 -> 8.4.0
- Bump Testcontainers 2.0.0 -> 2.0.3
- Bump springdoc 2.8.6 -> 3.0.2 (Spring Boot 4 compatible line)
- Bump JJWT 0.12.6 -> 0.12.7, centralized in parent POM
- Bump Cloudinary 2.0.0 -> 2.3.2, centralized in parent POM
- Override Jackson BOMs 2.20.2 -> 2.21.1 / 3.0.4 -> 3.1.0 (CVE-2026-29062)
- Override Kafka 4.1.1 -> 4.1.2 (CVE-2025-48734)
- Override lz4-java -> 1.8.1, protobuf-java -> 4.34.0 (transitive CVE fixes)
- Update README badges and tech stack versions
@tsekovTriesCoding tsekovTriesCoding merged commit f0a8b24 into main Mar 18, 2026
3 checks passed
@tsekovTriesCoding tsekovTriesCoding deleted the fix/backend-dependency-vulnerabilities branch March 18, 2026 14:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant