Ramsons dependency upgrades fixing vulns (Spring Boot, etc.)

Description

Upgrade Spring Boot from 3.2.3 to 3.3.7.

Note that OSS support for Spring Boot 3.2.x has ended 2024-11-23: https://spring.io/projects/spring-boot#support

Note that Ramsons requires Spring Boot 3.3.x: https://folio-org.atlassian.net/wiki/spaces/TC/pages/5058042/Ramsons#Ramsons-ThirdPartyLibraries/Frameworks

The Spring Boot upgrade indirectly upgrades kafka-clients from 3.6.1 to 3.7.2 fixing

Upgrade minio client from 8.5.9 to 8.5.15.

Upgrade folio-spring-base from 8.2.0 to 8.2.2.

The minio upgrade and the folio-spring-base upgrade indirectly upgrade bcprov-jdk18on from 1.77 to 1.78.1 fixing

The Spring Boot upgrade and the folio-spring-base upgrade indirectly upgrade spring-webmvc from 6.1.4 to 6.1.16 fixing

The Spring Boot upgrade and the folio-spring-base upgrade indirectly upgrade tomcat-embed-core from 10.1.19 to 10.1.34 fixing

The Spring Boot upgrade and the folio-spring-base upgrade indirectly upgrade spring-web from 6.1.4 to 6.1.16 fixing

Upgrade aws s3 client from 2.25.13 to 2.29.47. This indirectly upgrades netty-codec-http from 4.1.107.Final to 4.1.116.Final fixing

CSP Request Details

None

CSP Rejection Details

None

Potential Workaround

None

Checklist

hide

Activity

Show:

Tatsiana HryhoryevaJanuary 21, 2025 at 8:54 AM

Upload files with identifiers in “Bulk edit“ app verified for all record types (Instances, Holdings, Items, Users) on OKAPI, Eureka bugfest environments, works as expected

Done

Details

Assignee

Reporter

Labels

Priority

Development Team

Firebird

Fix versions

Release

Ramsons (R2 2024) Bug Fix

RCA Group

Related dependency upgrade

Affects versions

TestRail: Cases

Open TestRail: Cases

TestRail: Runs

Open TestRail: Runs

Created January 9, 2025 at 6:39 PM
Updated January 21, 2025 at 2:55 PM
Resolved January 10, 2025 at 1:08 PM
TestRail: Cases
TestRail: Runs