PXF 2.0 using Spring-Boot ecosystem component dependencies - Security vulnerability
- Dominant language
- C
- Stars
- 1.4k
- Forks
- 247
- Avg merge
- 4d 3h
- Merged PRs (30d)
- 39
Description
@tuhaihe Regarding PXF2.0, seems like using Spring Boot 2.5.12 ecosystem framework:
Is PXF built using Spring Boot 2.5.12 ecosystem components?
If yes, can this be patched to latest version (OR) removed, to make it supported by PXF avoiding vulnerabilities ?
I can see multiple Sprin-boot components:
spring-boot-gradle-plugin-2.5.12.jar
spring-boot-starter-web-2.5.12.jar
spring-boot-starter-tomcat-2.5.12.jar
spring-boot-actuator-2.5.12.jar
spring-boot-autoconfigure-2.5.12.jar
Contributor guide
Research direction
Start by locating the dependency declarations for the listed Spring Boot 2.5.12 components, including spring-boot-starter-web, spring-boot-starter-tomcat, spring-boot-actuator, and spring-boot-autoconfigure. Check which versions are supported and affected, then confirm whether the dependencies can be upgraded or removed without breaking PXF.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- spring-boot
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100