Skip to content

Commit 012de17

Browse files
fix(deps): pin spring-framework version to 7.0.8 in example apps (GHSA-h3qp-gqrc-q736)
Add ext['spring-framework.version'] override in both example Spring Boot apps (example-spring-boot-starter-web and example-spring-boot-starter-webflux), in lockstep with the resolutionStrategy floor added for spring-webmvc and spring-webflux in the root build.gradle. These examples use the Spring Dependency Management plugin's strict BOM import, which is not affected by resolutionStrategy.eachDependency and requires its own ext[] property override to move the floor, following the same pattern already used there for jackson, logback, netty and tomcat. Co-Authored-By: Catarina Correia <catarina.correia@getyourguide.com>
1 parent b8e1576 commit 012de17

2 files changed

Lines changed: 2 additions & 0 deletions

File tree

‎examples/example-spring-boot-starter-web/build.gradle‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@ ext['jackson-2-bom.version'] = '2.21.5'
1010
ext['logback.version'] = '1.5.34'
1111
ext['netty.version'] = '4.2.16.Final'
1212
ext['tomcat.version'] = '11.0.22'
13+
ext['spring-framework.version'] = '7.0.8'
1314

1415
dependencies {
1516
implementation project(':examples:examples-common')

‎examples/example-spring-boot-starter-webflux/build.gradle‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@ ext['jackson-2-bom.version'] = '2.21.5'
1010
ext['logback.version'] = '1.5.34'
1111
ext['netty.version'] = '4.2.16.Final'
1212
ext['tomcat.version'] = '11.0.22'
13+
ext['spring-framework.version'] = '7.0.8'
1314

1415
dependencies {
1516
implementation project(':examples:examples-common')

0 commit comments

Comments
 (0)