[SCA] Security upgrade @org.springframework:spring-web from 3.2.6.RELEASE to 6.2.17 #175
[SCA] Security upgrade @org.springframework:spring-web from 3.2.6.RELEASE to 6.2.17
#175gwnlng wants to merge 1 commit into
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-16109615 - https://snyk.io/vuln/SNYK-JAVA-ORGSPRINGFRAMEWORK-16109618
|
This is a major version upgrade from Spring Framework 3.2 to 6.2, which is a massive leap spanning three major versions (v4, v5, v6) and over a decade of evolution. This upgrade introduces substantial breaking changes that will require significant code and configuration refactoring. Key Breaking Changes:
Recommendation: This is a very high-effort migration that should be treated as a major project, not a simple dependency bump. A phased approach is recommended:
Automated refactoring tools like OpenRewrite can assist with some of the mechanical changes like package renaming. Sources:
|
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
This is a PR from Snyk, initiated by the Security team, to fix 6 vulnerabilities in the dependencies of this project.
Snyk changed the following file(s):
Important
#sca-supportSlack channel.References: