Skip to content

fix(deps): update dependency org.springframework.boot:spring-boot-starter-parent to v2.7.18 (wip) - #27

Open
mend-for-github-com[bot] wants to merge 1 commit into
wipfrom
whitesource-remediate/wip-spring-boot
Open

fix(deps): update dependency org.springframework.boot:spring-boot-starter-parent to v2.7.18 (wip)#27
mend-for-github-com[bot] wants to merge 1 commit into
wipfrom
whitesource-remediate/wip-spring-boot

fix(deps): update dependency org.springframework.boot:spring-boot-sta…

8d2ce4d
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / WhiteSource Security Check succeeded Aug 17, 2026 in 7m 46s

Security Report

❗️Scan Warnings: The scan completed with warnings. The integration encountered issues with one or more projects in this repository. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.

Scan Details Report

maven

/tmp/ws-scm/Spring4ShellExample/test-app/pom.xml

StepLevelDescriptionDetails
Preparing the project for scan⚠WarnOne or more of the installations failed[ERROR] [ERROR] Some problems were encountered while processing the POMs:
[FATAL] Non-resolvable parent POM for com.example:spring4shell-demo:0.0.1-SNAPSHOT: The following artifacts could not be resolved: org.springframework.boot:spring-boot-starter-parent:pom:2.7.18 (absent): Could not transfer artifact org.springframework.boot:spring-boot-starter-parent:pom:2.7.18 from/to central (https://rep...
Resolving the project⚠WarnSome problems occurred while performing the resolution operation
  • Failed to execute command: mvn org.apache.maven.plugins:maven-dependency-plugin:3.6.0:tree -DoutputFile=whitesource_mvn_dependency_tree.txt -Dverbose -DoutputType=text -T1 -B
    Error lines:
    [NOTE: Picked up JDK_JAVA_OPTIONS: --add-opens java.base/java.util=ALL-UNNAMED --add-opens java.base/sun.reflect.generics.reflectiveObjects=ALL-UNNAMED]
    Output lines:
    [[INFO] Scanning for project...
  • Fallback is used, returns direct dependencies only

https://vonagecc.jfrog.io/artifactory

StepLevelDescriptionDetails
Checking registry connectivity⚠WarnProblem occurred while connecting to the private registry host server, private registry returned 401 - Unauthorized{"errors":[{"code":"UNAUTHORIZED","message":"Invalid token, parse"}]}

https://vonagecc.jfrog.io/artifactory/maven

StepLevelDescriptionDetails
Checking registry connectivity⚠WarnProblem occurred while connecting to the private registry host server, private registry returned 401 - Unauthorized{"errors":[{"code":"UNAUTHORIZED","message":"Invalid token, parse"}]}

✔️ 👍 You have successfully remediated 88 vulnerabilities in this branch:
VulnerabilityVulnerable Library
CVE-2023-20861spring-expression-5.2.10.RELEASE.jar
CVE-2022-22950spring-expression-5.2.10.RELEASE.jar
CVE-2025-11226logback-core-1.2.3.jar
CVE-2020-36518jackson-databind-2.11.3.jar
CVE-2022-38750snakeyaml-1.26.jar
CVE-2022-41854snakeyaml-1.26.jar
CVE-2026-54513jackson-databind-2.11.3.jar
CVE-2026-40477thymeleaf-spring5-3.0.11.RELEASE.jar
CVE-2022-38752snakeyaml-1.26.jar
CVE-2026-41849spring-expression-5.2.10.RELEASE.jar
CVE-2025-22235spring-boot-2.3.5.RELEASE.jar
CVE-2026-22745spring-webmvc-5.2.10.RELEASE.jar
CVE-2024-22259spring-web-5.2.10.RELEASE.jar
CVE-2026-22741spring-webmvc-5.2.10.RELEASE.jar
CVE-2022-22970spring-beans-5.2.10.RELEASE.jar
CVE-2026-49844log4j-api-2.13.3.jar
CVE-2026-41851spring-expression-5.2.10.RELEASE.jar
CVE-2023-6378logback-classic-1.2.3.jar
CVE-2021-22096spring-webmvc-5.2.10.RELEASE.jar
CVE-2021-42550logback-classic-1.2.3.jar
CVE-2021-46877jackson-databind-2.11.3.jar
CVE-2024-38820spring-context-5.2.10.RELEASE.jar
CVE-2025-52999jackson-core-2.11.3.jar
CVE-2026-41850spring-expression-5.2.10.RELEASE.jar
CVE-2026-22735spring-webmvc-5.2.10.RELEASE.jar
CVE-2026-41853spring-webmvc-5.2.10.RELEASE.jar
CVE-2026-40477thymeleaf-3.0.11.RELEASE.jar
CVE-2026-1225logback-core-1.2.3.jar
WS-2022-0468jackson-core-2.11.3.jar
CVE-2021-42550logback-core-1.2.3.jar
CVE-2026-54515jackson-databind-2.11.3.jar
CVE-2023-6378logback-core-1.2.3.jar
CVE-2025-49128jackson-core-2.11.3.jar
CVE-2024-12798logback-classic-1.2.3.jar
CVE-2026-41843spring-webmvc-5.2.10.RELEASE.jar
CVE-2026-41845spring-webmvc-5.2.10.RELEASE.jar
CVE-2026-9828logback-core-1.2.3.jar
CVE-2023-6481logback-core-1.2.3.jar
CVE-2026-40478thymeleaf-spring5-3.0.11.RELEASE.jar
CVE-2026-13006logback-core-1.2.3.jar
CVE-2016-1000027spring-web-5.2.10.RELEASE.jar
CVE-2026-54512jackson-databind-2.11.3.jar
CVE-2024-38808spring-expression-5.2.10.RELEASE.jar
CVE-2024-38809spring-web-5.2.10.RELEASE.jar
CVE-2026-41841spring-webmvc-5.2.10.RELEASE.jar
CVE-2023-20863spring-expression-5.2.10.RELEASE.jar
CVE-2024-38820spring-web-5.2.10.RELEASE.jar
CVE-2021-22060spring-web-5.2.10.RELEASE.jar
CVE-2024-38828spring-webmvc-5.2.10.RELEASE.jar
CVE-2022-22965spring-beans-5.2.10.RELEASE.jar
CVE-2025-41249spring-core-5.2.10.RELEASE.jar
WS-2021-0616jackson-core-2.11.3.jar
CVE-2026-22735spring-web-5.2.10.RELEASE.jar
CVE-2022-38751snakeyaml-1.26.jar
CVE-2025-41242spring-beans-5.2.10.RELEASE.jar
CVE-2024-22262spring-web-5.2.10.RELEASE.jar
WS-2026-0003jackson-core-2.11.3.jar
CVE-2022-22968spring-context-5.2.10.RELEASE.jar
CVE-2024-38819spring-webmvc-5.2.10.RELEASE.jar
CVE-2026-41852spring-expression-5.2.10.RELEASE.jar
CVE-2026-40973spring-boot-2.3.5.RELEASE.jar
CVE-2022-38749snakeyaml-1.26.jar
CVE-2024-38816spring-webmvc-5.2.10.RELEASE.jar
CVE-2024-22243spring-web-5.2.10.RELEASE.jar
CVE-2022-42004jackson-databind-2.11.3.jar
CVE-2024-12798logback-core-1.2.3.jar
CVE-2026-54514jackson-databind-2.11.3.jar
CVE-2022-25857snakeyaml-1.26.jar
CVE-2021-22096spring-web-5.2.10.RELEASE.jar
CVE-2026-41901thymeleaf-3.0.11.RELEASE.jar
CVE-2026-41848spring-core-5.2.10.RELEASE.jar
CVE-2023-38286thymeleaf-3.0.11.RELEASE.jar
CVE-2022-22970spring-core-5.2.10.RELEASE.jar
CVE-2026-40478thymeleaf-3.0.11.RELEASE.jar
CVE-2022-42003jackson-databind-2.11.3.jar
CVE-2026-41901thymeleaf-spring5-3.0.11.RELEASE.jar
WS-2021-0616jackson-databind-2.11.3.jar
CVE-2022-1471snakeyaml-1.26.jar
CVE-2026-50193jackson-databind-2.11.3.jar
CVE-2026-41842spring-webmvc-5.2.10.RELEASE.jar
CVE-2026-10532logback-core-1.2.3.jar
CVE-2024-12801logback-core-1.2.3.jar
CVE-2026-41844spring-webmvc-5.2.10.RELEASE.jar
CVE-2023-20883spring-boot-autoconfigure-2.3.5.RELEASE.jar
CVE-2026-41846spring-webmvc-5.2.10.RELEASE.jar
CVE-2026-19880logback-classic-1.2.3.jar
CVE-2025-22233spring-context-5.2.10.RELEASE.jar
CVE-2022-22965spring-boot-starter-web-2.3.5.RELEASE.jar

Base branch total remaining vulnerabilities: 88
Base branch commit: 302c67d57ff33993b59b4e4a0302421181d2e09c


Total libraries scanned: 0

Scan token: d82b9c267f6a46f88b985676ee903e97