Skip to content

Dependency updates to eliminate vulnerabilities discovered by dependency-check

bhill6@wisc.edu requested to merge dependency_updates into main

Eliminated all CRITICAL and HIGH except for CVE-2016-1000027 (which more or less forbids the use of Spring since 2016 -- it's moderately controversial.

@road

Merge request reports