eclipse-rdf4j / rdf4j

Eclipse RDF4J: scalable RDF for Java
https://rdf4j.org/
BSD 3-Clause "New" or "Revised" License
361 stars 163 forks source link

Upgrade spring to 5.3.37 #5048

Closed barthanssens closed 2 months ago

barthanssens commented 3 months ago

Current Behavior

Congrats on releasing 5.0 ;-)

I've noticed, when releasing the docker workbench image, there are a few vulnerabilities in spring framework itself (which may or may not affect RDF4J workbench)

Expected Behavior

Upgrading to the latest (patch) release of spring should fix most (but probably not all) reported CVEs for spring dependencies

Steps To Reproduce

No response

Version

5.0.0

Are you interested in contributing a solution yourself?

Yes

Anything else?

No response