Skip to content

DAPR 1.6 uses Spring Boot Starter Web with vulnerability #782

Description

@sujitp149

Ask your question here

DAPR 1.6 uses spring-boot-starter-web/2.3.5.RELEASE which has vulnerability. Any plans to upgrade the Spring Boot Starter Web version without vulnerability as many organization don't allow any artifacts with open vulnerability ?

DAPR

Activity

pravinpushkar commented on Sep 16, 2022

@pravinpushkar
Contributor

@sujitp149 Thanks for reporting this. We can try bumping the version to 2.7.3. Please feel free to submit a PR, we can see if that is breaking anything.

rowi1de commented on Sep 22, 2022

@rowi1de

Out of curiosity: why is spring-boot-starter-web included and not spring-boot-starter-webflux, as all methods seem to be non-blocking?

artursouza commented on Nov 7, 2022

@artursouza
Contributor

Out of curiosity: why is spring-boot-starter-web included and not spring-boot-starter-webflux, as all methods seem to be non-blocking?

Great point, I think we should offer webflux but it should probably be a new artifact so it does not break existing users.

added this to the v1.8 milestone on Nov 7, 2022
self-assigned this
on Feb 1, 2023
modified the milestones: v1.8, v1.9 on Feb 3, 2023

artursouza commented on Feb 3, 2023

@artursouza
Contributor

I have added the PR above to the release. I will keep this open to confirm that it will really remove the vulnerability. If not, we will need to upgrade to a new major version in the next release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions