feat: update spring-boot version to 5.3.20 #1458
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
📝 Description
The known Remote Code Execution in Spring Beans is identified in
graphql-kotlin-spring-client
.main
already consumes5.3.20
Forcing usage of
graphql-java:17.2
spring-boot-starter-parent:2.7.0
pullsgraphql-java:18
andgraphql-kotlin
5.x.x is not compatible with that version, when clients usingspring-boot-starter-parent:2.7.0
andgraphql-kotlin
5.x.x the build will trigger a resolution error to force them to usegraphql-java:17.2
🔗 Related Issues