[Snyk] Fix for 5 vulnerabilities - #12
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGHIBERNATE-15702517 - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-15701845 - https://snyk.io/vuln/SNYK-JAVA-ORGHIBERNATE-15702518 - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-15701755 - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-15701756
|
This upgrade involves multiple major version jumps for critical Spring and AWS libraries, introducing significant breaking changes. All three upgrades are high-risk and will require substantial code and configuration updates, along with a migration to newer versions of Spring Boot, Spring Framework, and the AWS SDK. 1. com.github.derjust:spring-data-dynamodb (4.3.1 → 5.0.3)Risk: HIGH This is a major version upgrade that ties the library to a newer version of the Spring Framework. The Breaking Changes:
Recommendation: This upgrade is a major undertaking. Before proceeding, evaluate migrating to the actively maintained fork of 2. org.springframework.cloud:spring-cloud-function-adapter-aws (1.0.0.RC2 → 3.2.0)Risk: HIGH This is a massive upgrade from a release candidate to a stable version 3.x, which represents a complete rewrite of the library. Breaking Changes:
|
⛔ Snyk checks have failed. 4 issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
Snyk has created this PR to fix 5 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
pom.xmlVulnerabilities that will be fixed with an upgrade:
SNYK-JAVA-ORGHIBERNATE-15702517
4.3.1->5.0.3Major version upgradeNo Path FoundNo Known ExploitSNYK-JAVA-ORGSPRINGFRAMEWORK-15701845
2.6.6.RELEASE->4.5.10Major version upgradeNo Path FoundNo Known ExploitSNYK-JAVA-ORGHIBERNATE-15702518
4.3.1->5.0.3Major version upgradeNo Path FoundNo Known ExploitSNYK-JAVA-ORGSPRINGFRAMEWORK-15701755
1.0.0.RC2->3.2.0org.springframework.data:spring-data-rest-webmvc:
2.6.6.RELEASE->4.5.10Major version upgradeNo Path FoundNo Known ExploitSNYK-JAVA-ORGSPRINGFRAMEWORK-15701756
2.6.6.RELEASE->4.5.10Major version upgradeNo Path FoundNo Known ExploitBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Arbitrary Code Injection
🦉 Cross-site Scripting (XSS)
🦉 Directory Traversal