[Snyk] Fix for 1 vulnerabilities - #4
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551
|
This upgrade includes a major version increase for Spring Boot from 2.x to 3.x, which introduces significant breaking changes. The other upgrades are minor and less likely to cause issues, but the Spring Boot migration requires careful attention.
This is a major upgrade with several critical breaking changes that require developer action:
This is a minor version upgrade. While it spans several versions, there are no major breaking API changes documented. Key changes include:
This is a minor update. Version 1.7.0 is the last major open-source release that supports Spring Boot 2.x. For Spring Boot 3.x, you must migrate to the Recommendation: This upgrade cannot be merged directly. A dedicated migration effort is required to address the breaking changes in Spring Boot 3. Start by upgrading your application to the latest Spring Boot 2.7.x release and Java 17. Then, follow the official Spring Boot 3.0 Migration Guide to address the Jakarta EE namespace changes, security configurations, and updated properties.
|
Snyk has created this PR to fix 1 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
pom.xmlVulnerabilities that will be fixed with an upgrade:
SNYK-JAVA-COMFASTERXMLJACKSONCORE-15907551
1.6.5->1.7.0Major version upgradeNo Known ExploitBreaking Change Risk
Vulnerabilities that could not be fixed
com.fasterxml.jackson.core:jackson-databind@2.13.1tocom.fasterxml.jackson.core:jackson-databind@2.21.2; Reasoncould not apply upgrade, dependency is managed externally; Location:https://maven-central.storage-download.googleapis.com/maven2/com/fasterxml/jackson/jackson-bom/2.13.1/jackson-bom-2.13.1.pomcom.fasterxml.jackson.datatype:jackson-datatype-jsr310@2.13.1tocom.fasterxml.jackson.datatype:jackson-datatype-jsr310@2.21.2; Reasoncould not apply upgrade, dependency is managed externally; Location:https://maven-central.storage-download.googleapis.com/maven2/com/fasterxml/jackson/jackson-bom/2.13.1/jackson-bom-2.13.1.pomorg.springframework.boot:spring-boot-starter-web@2.6.3toorg.springframework.boot:spring-boot-starter-web@3.5.13; Reasoncould not apply upgrade, dependency is managed externally; Location:https://maven-central.storage-download.googleapis.com/maven2/org/springframework/boot/spring-boot-dependencies/2.6.3/spring-boot-dependencies-2.6.3.pomImportant
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Allocation of Resources Without Limits or Throttling