Skip to content

Conversation

@IAmATeaPot418
Copy link
Owner

@IAmATeaPot418 IAmATeaPot418 commented Mar 9, 2022

🚀 Endor Labs Automated Dependency Update 🚀

📝 Summary

This PR updates dependencies to improve security:

📦 Dependencies Updated:

Dependency Name Update Version (From ➡️ To) Update Risk Age of Dependency
spring-boot-starter-web 2.5.4 ➡️ 2.6.1 High 12 months

📋 Release Notes (Click to expand)

Changes in Dependency Versions:

spring-boot-starter-web

🛡️ Security Impact

Summary of Fixed Issues:

Severity Count
High 3
Medium 2
🔍 Detailed Vulnerability Summary (Click to expand)
Advisory Reachability Severity EPSS
CVE-2021-22096 Reachable High 0.85
CVE-2021-22097 Reachable High 0.84
CVE-2021-22098 Reachable High 0.88
CVE-2020-25649 Reachable Medium 0.62
CVE-2020-35490 Reachable Medium 0.60
CVE-2021-44228 Reachable High 0.93

📚 Reminders

  • 🙉 Ignore: If you don't wish to receive this update again, simply close this PR.

"Fear of change leads to the dark side. Embrace updates, you must. Stronger, safer, your code will be."

❤️ From Endor Labs

@ng-karen
Copy link

ng-karen commented Aug 8, 2024

🚀 Endor Labs Automated Dependency Update 🚀

📝 Summary

This PR updates dependencies to improve security:

📦 Dependencies Updated:

Dependency Name Update Version (From ➡️ To) Update Risk Age of Dependency
spring-boot-starter-web 2.5.4 ➡️ 2.6.1 High 12 months

📋 Release Notes (Click to expand)

Changes in Dependency Versions:

spring-boot-starter-web

🛡️ Security Impact

Summary of Fixed Issues:

Severity Count
🔴 High 3
🟠 Medium 2
🔍 Detailed Vulnerability Summary (Click to expand)
Advisory Reachability Severity EPSS
CVE-2021-22096 Reachable 🔴 High 0.85
CVE-2021-22097 Reachable 🔴 High 0.84
CVE-2021-22098 Reachable 🔴 High 0.88
CVE-2020-25649 Reachable 🟠 Medium 0.62
CVE-2020-35490 Reachable 🟠 Medium 0.60
CVE-2021-44228 Reachable 🔴 High 0.93

📚 Reminders

  • 🛠️ Test: Remember to ensure your tests pass and ensure this change doesn't impact your application before you merge.
  • 🙉 Ignore: If you don't wish to receive this update again, simply close this PR.

"Fear of change leads to the dark side. Embrace updates, you must. Stronger, safer, your code will be."

❤️ From Endor Labs

May the git push -f be with you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants