[ https://issues.apache.org/jira/browse/KNOX-3121?focusedWorklogId=966054&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-966054 ]
ASF GitHub Bot logged work on KNOX-3121: ---------------------------------------- Author: ASF GitHub Bot Created on: 14/Apr/25 14:52 Start Date: 14/Apr/25 14:52 Worklog Time Spent: 10m Work Description: smolnar82 commented on PR #1017: URL: https://github.com/apache/knox/pull/1017#issuecomment-2801986573 I think there is an actual issue with the new version of Spring, which should be handled (exclude/upgrade, etc...). I'm glad we have the dependency enforcer tool as part of our builds. Issue Time Tracking ------------------- Worklog Id: (was: 966054) Time Spent: 2h (was: 1h 50m) > Upgrade spring due to CVEs > -------------------------- > > Key: KNOX-3121 > URL: https://issues.apache.org/jira/browse/KNOX-3121 > Project: Apache Knox > Issue Type: Task > Reporter: Preetesh Verma > Priority: Major > Time Spent: 2h > Remaining Estimate: 0h > > upgrade spring from 5.3.21 to spring:5.3.39 > h4. -- This message was sent by Atlassian Jira (v8.20.10#820010)