Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

new release to bump dependency spring-core #429

Closed
jesperronn opened this issue May 14, 2024 · 3 comments
Closed

new release to bump dependency spring-core #429

jesperronn opened this issue May 14, 2024 · 3 comments
Assignees
Labels

Comments

@jesperronn
Copy link

Hi there

https://mvnrepository.com/artifact/org.springframework.retry/spring-retry/2.0.5 reports that spring-core dependency has one vulnerability.

2 questions:

  1. would it be possible for you to prepare a new release that updates the dependency? (seems like Dependabot is not configured correct to catch that)

  2. Are you aware of a workaround that can be used until a new release is ready. If so, please provide an example.

Thanks for your time and effort maintaining this project ❤️

@artembilan artembilan added this to the 2.0.6 milestone May 14, 2024
@artembilan
Copy link
Member

We have plans to release a new version of library this Friday. That’s where those dependencies are going to be update.

Thank you for the report!

@snicoll
Copy link
Member

snicoll commented May 14, 2024

There’s no need for us to release anything for you to get the fix in spring-core.

spring retry does not need a particular bug fix version of spring core and you should manage the framework version with the bom if you’re not using spring boot.

@snicoll
Copy link
Member

snicoll commented May 15, 2024

I am closing this in favor of #435 as I don't want to imply that the upgrade is necessary for what's described here.

@snicoll snicoll closed this as not planned Won't fix, can't repro, duplicate, stale May 15, 2024
@snicoll snicoll removed this from the 2.0.6 milestone May 15, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants