Skip to content

chore(deps): bump spring boot to 3.5.14#1817

Merged
netomi merged 2 commits intoeclipse-openvsx:mainfrom
vinokurig:update-spring-boot
May 6, 2026
Merged

chore(deps): bump spring boot to 3.5.14#1817
netomi merged 2 commits intoeclipse-openvsx:mainfrom
vinokurig:update-spring-boot

Conversation

@vinokurig
Copy link
Copy Markdown

@vinokurig vinokurig commented May 6, 2026

Fix CVE-2026-40975: Random value property source uses a weak PRNG unsuitable for secrets, see: https://spring.io/security/cve-2026-40975

@netomi
Copy link
Copy Markdown
Contributor

netomi commented May 6, 2026

ty for raising that PR

Edit: I removed some overrides that are not needed anymore after the bump

vinokurig and others added 2 commits May 6, 2026 17:12
@netomi netomi force-pushed the update-spring-boot branch from 11422a4 to f0ad328 Compare May 6, 2026 15:13
@netomi netomi merged commit 1a8c634 into eclipse-openvsx:main May 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants