onichols-pivotal opened a new pull request #7531:
URL: https://github.com/apache/geode/pull/7531


   see https://github.com/spring-projects/spring-framework/issues/24434
   
   If we're picking up spring latest, I wonder, would it be wise to bump other 
spring-* latests too (rather than wonder what versions of what are compatible 
with each other)?  E.g. maybe also bump:
   
   spring-boot-starter 2.4.2 -> 2.6.5
   spring-hateoas 1.2.3 -> 1.4.1
   spring-ldap 2.3.4 -> 2.3.6
   spring-security 5.4.8 -> 5.6.2
   spring-session 2.4.2 -> 2.6.2
   
   While it seems likely for 1.14 it should be fine either way, for backporting 
to 1.13 and 1.12, it might be easier to just have a consistent set to go to, 
since those branches would have to make a bigger jump from spring 5.2 (which is 
now out of support) so definitely won't have the option of keeping their 
existing versions of other spring-*


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


Reply via email to