From bd133141203cc02c4948a5ee73a3639b788a4225 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 23 Jun 2025 22:00:38 +0000 Subject: [PATCH] build(deps): bump org.apache.tomcat.embed:tomcat-embed-core Bumps org.apache.tomcat.embed:tomcat-embed-core from 10.1.42 to 11.0.8. --- updated-dependencies: - dependency-name: org.apache.tomcat.embed:tomcat-embed-core dependency-version: 11.0.8 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- build.gradle | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/build.gradle b/build.gradle index 81c7f89..e094baf 100644 --- a/build.gradle +++ b/build.gradle @@ -72,7 +72,7 @@ subprojects { implementation("org.springframework:spring-web:6.2.8") { because("versions below 6.2.8 have security vulnerabilities including CVE-2024-38820 - see dependabot #12") } - implementation("org.apache.tomcat.embed:tomcat-embed-core:10.1.42") { + implementation("org.apache.tomcat.embed:tomcat-embed-core:11.0.8") { because("versions below 10.1.42 have security vulnerabilities including CVE-2024-56337 - see dependabot #13") } }