Skip to content

Conversation

@tomasz-tylenda-sonarsource
Copy link
Contributor

@tomasz-tylenda-sonarsource tomasz-tylenda-sonarsource commented May 23, 2025

SONARJAVA-5593

While the dependency on 6.4.5 was not shipped and threfore did not create a vulnerability, it still raised an alert. The easiest way to fix it is to upgrade the library.

@tomasz-tylenda-sonarsource tomasz-tylenda-sonarsource changed the title Update spring-security-core from 6.4.5 to 6.4.6 to address CVE-2025-41232 Update spring-security-core from 6.4.5 to 6.4.6 to suppress alert about CVE-2025-41232 May 26, 2025
@sonarqube-next
Copy link

Quality Gate passed Quality Gate passed

Issues
0 New issues
0 Fixed issues
0 Accepted issues

Measures
0 Security Hotspots
0 Dependency risks
No data about Coverage
No data about Duplication

See analysis details on SonarQube

@tomasz-tylenda-sonarsource tomasz-tylenda-sonarsource changed the title Update spring-security-core from 6.4.5 to 6.4.6 to suppress alert about CVE-2025-41232 SONARJAVA-5593 Update spring-security-core from 6.4.5 to 6.4.6 to suppress alert about CVE-2025-41232 May 26, 2025
@dorian-burihabwa-sonarsource dorian-burihabwa-sonarsource merged commit c44fcee into master May 26, 2025
17 of 18 checks passed
@dorian-burihabwa-sonarsource dorian-burihabwa-sonarsource deleted the mend-update-spring-security-core branch May 26, 2025 13:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants