didi / KnowStreaming

一站式云原生实时流数据平台,通过0侵入、插件化构建企业级Kafka服务,极大降低操作、存储和管理实时流数据门槛
https://knowstreaming.com
GNU Affero General Public License v3.0
6.99k stars 1.28k forks source link

fix(sec): upgrade org.springframework.boot:spring-boot-actuator-autoconfigure to 3.0.6 #1012

Open VincennLiu opened 1 year ago

VincennLiu commented 1 year ago

What happened?

There are 1 security vulnerabilities found in org.springframework.boot:spring-boot-actuator-autoconfigure 2.3.7.RELEASE

What did I do?

Upgrade org.springframework.boot:spring-boot-actuator-autoconfigure from 2.3.7.RELEASE to 3.0.6 for vulnerability fix

What did you expect to happen?

Ideally, no insecure libs should be used.

The specification of the pull request

PR Specification from OSCS