This is an automated email from the ASF dual-hosted git repository.

lukaszlenart pushed a commit to branch WW-5717-spring-7.0.9
in repository https://gitbox.apache.org/repos/asf/struts.git

commit c373c531285e2a3aaa0fb1349c75209bd4be973b
Author: Lukasz Lenart <[email protected]>
AuthorDate: Fri Sep 11 07:25:19 2026 +0200

    WW-5717 build: bump Spring Framework to 7.0.9 in the jakartaee11 profile
    
    7.0.9 is the first OSS Spring Framework release covering the
    2026-08-20 advisory wave (CVE-2026-47883..47893, 59280..59283, 59313,
    59314) that the OWASP dependency-check run flags on spring-core 7.0.8.
    None of the 17 sits on a code path Struts executes (they are Spring
    MVC/WebFlux/RSocket, SpEL, DataBinder and UrlHandlerFilter issues),
    so this is dependency hygiene, not a Struts fix.
    
    The default profile stays on 6.2.19: it is the last OSS 6.2.x release,
    6.2.20 is Enterprise-Support-only, and CI scans the jakartaee11 profile.
    
    Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
---
 pom.xml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/pom.xml b/pom.xml
index 1c23d29ae..3a89f5300 100644
--- a/pom.xml
+++ b/pom.xml
@@ -165,7 +165,7 @@
             <id>jakartaee11</id>
             <properties>
                 <jakarta-ee.version>11.0.0</jakarta-ee.version>
-                <spring.version>7.0.8</spring.version>
+                <spring.version>7.0.9</spring.version>
             </properties>
         </profile>
         <profile>

Reply via email to