Fix CVEs for mssql-jdbc and lz4-java#654
Merged
onobc merged 1 commit intospring-cloud:mainfrom Feb 10, 2026
Merged
Conversation
mamachanko
approved these changes
Feb 9, 2026
e10d0ff to
6dad6ac
Compare
Removes the previous override of `mssql-jdbc` which is no longer required as Spring Boot `3.4.13` dependency management updates the version to the fixed version `12.8.2.jre11`. Moves the previous override of `lz4-java` to where the dependency is used - in the Kafka binder apps only. Also update from version `1.8.1` to `1.10.3` as there are more recent CVEs since last update. Finally, adds CVE-2025-59250 to the trivyignore list because Trivy is incorrectly reporting that we are using version `12.8.2` when we are actually using the fixed version `12.8.2.jre11`. Signed-off-by: Chris Bono <chris.bono@broadcom.com>
6dad6ac to
699c81f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Moves the previous override of
mssql-jdbcto where the dependency is used (rather than for all apps) in thejdbc-sourceandjdbc-sinkapps. Also fixes CVE-2025-8916 by excluding the transitive dependency onorg.bouncycastle:bcpkix-jdk18on:1.78frommssql-jdbcand instead directly brings in Bouncycastle version1.79.Moves the previous override of
lz4-javato where the dependency is used - in the Kafka binder apps only. Also fixes CVE-2025-66566 by excluding the flawed version oflz4-javafromkafka-clientsand instead brings in updatedlz4-javaversion1.10.3.