[Snyk] Security upgrade org.springframework.boot:spring-boot-starter-web from 2.6.6 to 4.0.0 - #51
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHETOMCATEMBED-16691231
|
This is a major version upgrade from Spring Boot 2.6.6 to a hypothetical 4.0.0. This leap crosses two major, highly impactful releases: 3.0 and 4.0. The upgrade requires significant developer action due to fundamental platform changes. Spring Boot 3.0 Breaking Changes:
Spring Boot 4.0 Breaking Changes:
Recommendation: This upgrade cannot be performed directly. A step-by-step migration is required:
Source: Spring Boot 3.0 Release Notes, Spring Boot 4.0 Release Notes
|
⛔ Snyk checks have failed. 4 issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
|
Closing this PR as it has been inactive for a long period. Please reopen if this is still relevant. |
Snyk has created this PR to fix 1 vulnerabilities in the maven dependencies of this project.
Snyk changed the following file(s):
converter-codegen-testapp/pom.xmlVulnerabilities that will be fixed with an upgrade:
SNYK-JAVA-ORGAPACHETOMCATEMBED-16691231
2.6.6->4.0.0Major version upgradeNo Path FoundNo Known ExploitBreaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Improper Authentication