Skip to content

Conversation

@mend-for-github-com
Copy link
Contributor

This PR contains the following updates:

Package Type Update Change
org.springframework.boot:spring-boot-starter-webflux (source) dependencies patch 3.5.5 -> 3.5.6

By merging this PR, the issue #562 will be automatically resolved and closed:

Severity CVSS Score Vulnerability
High High 7.5 CVE-2025-55163
High High 7.5 CVE-2025-58056
High High 7.5 CVE-2025-58057
High High 7.5 CVE-2025-58057
High High 7.5 CVE-2025-58057

Release Notes

spring-projects/spring-boot (org.springframework.boot:spring-boot-starter-webflux)

v3.5.6

🐞 Bug Fixes

  • Quoted -D arguments break system property resolution on Linux with Spring AOT #​47166
  • Groovy Templates fails with an NPE when rendering an auto new line #​47139
  • available() does not behave correctly when reading stored entries from a NestedJarFile #​47057
  • spring-boot-docker-compose doesn't create service connections when image has registry host but not project #​47019
  • Flyway Ignore Migration Patterns setting can't be set to an empty string #​47013

📔 Documentation

  • Default value of server.tomcat.resource.cache-ttl is not documented #​47253
  • Document Java 25 support #​47245
  • Fix links to Flyway reference documentation #​46988
  • Clarify Javadoc of Customizer interfaces about overriding behavior #​46942

🔨 Dependency Upgrades

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Chanwon-Seo, @​doljae, @​izeye, and @​quaff


  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Oct 27, 2025
@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Oct 27, 2025
@reta reta merged commit e7a9f02 into main Oct 27, 2025
13 checks passed
@mend-for-github-com mend-for-github-com bot deleted the whitesource-remediate/spring-boot branch October 27, 2025 13:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by Mend

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants