Skip to content

Bump Spring Framework from 5.3.31 to 5.3.39#2500

Merged
RaigorJiang merged 1 commit intoapache:masterfrom
RaigorJiang:cve-spring
Jan 31, 2026
Merged

Bump Spring Framework from 5.3.31 to 5.3.39#2500
RaigorJiang merged 1 commit intoapache:masterfrom
RaigorJiang:cve-spring

Conversation

@RaigorJiang
Copy link
Contributor

Fix CVE:

Note that version 5.3.39 is the last open-source version of the Spring Framework 5.3.x series.

@RaigorJiang RaigorJiang added this to the 3.1.0 milestone Jan 31, 2026
@RaigorJiang RaigorJiang added the dependencies Pull requests that update a dependency file label Jan 31, 2026
@codecov-commenter
Copy link

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 79.47%. Comparing base (a8ba448) to head (a68fd09).
⚠️ Report is 72 commits behind head on master.

Additional details and impacted files
@@             Coverage Diff              @@
##             master    #2500      +/-   ##
============================================
- Coverage     80.10%   79.47%   -0.64%     
- Complexity     1113     1127      +14     
============================================
  Files           204      208       +4     
  Lines          3821     3907      +86     
  Branches        445      465      +20     
============================================
+ Hits           3061     3105      +44     
- Misses          570      602      +32     
- Partials        190      200      +10     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@RaigorJiang RaigorJiang merged commit 86dc57b into apache:master Jan 31, 2026
15 checks passed
@RaigorJiang RaigorJiang deleted the cve-spring branch January 31, 2026 10:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants