Flowable 8.0.0 (27 Feb 2026) is the latest release. A Trivy scan of wars/flowable-rest.war from the 8.0.0 distribution reports 69 high and critical findings in bundled libraries. Every one has a fixed version on the same major line:
| Library |
In 8.0.0 |
Fixed in |
| Spring Boot |
4.0.2 |
4.0.6 |
| Spring Framework |
7.0.3 |
7.0.9 |
| Spring Security |
7.0.2 |
7.0.5 |
| Tomcat embed |
11.0.15 |
11.0.22 |
| Jackson 2 |
2.20.2 |
2.21.7 |
| Jackson 3 (tools.jackson) |
3.0.4 |
3.1.7 (see #4300) |
| Netty |
4.2.9.Final |
4.2.17.Final |
| Kafka clients |
4.1.1 |
4.1.2 |
| RabbitMQ amqp-client |
5.27.1 |
5.34.0 |
| Micrometer |
1.16.2 |
1.16.6 |
| HttpCore 5 |
5.3.6 |
5.4.3 |
| lz4-java |
1.8.0 |
1.8.1 |
We can see dependency updates on main (for example "Bump dependency versions" in May), but they aren't in a release yet. Could you publish an 8.0.1 with the updated dependencies, or say when the next release is planned? Users who ship the REST application unmodified currently have to choose between patching jars themselves and accepting the findings.
Related: #4300, and the open deserialization reports #4289 to #4293.
We can help test a release candidate against our integration's contract tests.
Flowable 8.0.0 (27 Feb 2026) is the latest release. A Trivy scan of
wars/flowable-rest.warfrom the 8.0.0 distribution reports 69 high and critical findings in bundled libraries. Every one has a fixed version on the same major line:We can see dependency updates on
main(for example "Bump dependency versions" in May), but they aren't in a release yet. Could you publish an 8.0.1 with the updated dependencies, or say when the next release is planned? Users who ship the REST application unmodified currently have to choose between patching jars themselves and accepting the findings.Related: #4300, and the open deserialization reports #4289 to #4293.
We can help test a release candidate against our integration's contract tests.