Skip to content

POPSCI-450: Update dependencies to address CVE vulnerabilities#56

Merged
Nahomtes merged 2 commits into2.0.0from
POPSCI-450
Mar 9, 2026
Merged

POPSCI-450: Update dependencies to address CVE vulnerabilities#56
Nahomtes merged 2 commits into2.0.0from
POPSCI-450

Conversation

@Nahomtes
Copy link

@Nahomtes Nahomtes commented Mar 5, 2026

This PR updates several dependencies to remediate known CVEs and security advisories.

Dependency updates

Verification

fix: update dependencies to address CVE vulnerabilities

- log4j-api/log4j-core: 2.24.3 → 2.25.3 (CVE-2025-68161, MEDIUM)
- tomcat-embed-core: 11.0.10 → 11.0.14 (CVE-2025-55752 HIGH, CVE-2025-66614 MEDIUM)
- opensearch-rest-client/opensearch-rest-high-level-client: 2.11.1 → 2.19.4 (CVE-2025-9624, HIGH)
@Nahomtes Nahomtes marked this pull request as ready for review March 5, 2026 16:46
@Nahomtes Nahomtes had a problem deploying to ccdi-manager-nonprod March 5, 2026 18:05 — with GitHub Actions Failure
Import jackson-bom at 2.18.6 and remove hardcoded jackson-dataformat-yaml 2.15.2 so jackson-core resolves to 2.18.6.
@Nahomtes Nahomtes merged commit 5e25fe9 into 2.0.0 Mar 9, 2026
2 of 3 checks passed
@Nahomtes Nahomtes deleted the POPSCI-450 branch March 9, 2026 21:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants