FIREFLY-1805: dependency security patches #1856
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Ticket: https://jira.ipac.caltech.edu/browse/FIREFLY-1805
Additional changes here: https://github.com/IPAC-SW/irsa-ife/pull/441
irsa-ife
We reduced the vulnerabilities from 13 critical and 25 high to 1 critical and 12 high.
The remaining critical issue originates from spring-jdbc, which is outdated and currently has no available fix. Upgrading it would require code changes to critical operations, so we may need to create a separate ticket and schedule it for a later phase.
Test:
https://firefly-1805-jar-security.irsakubedev.ipac.caltech.edu/irsaviewer/
https://fireflydev.ipac.caltech.edu/firefly-1805-jar-security/firefly/
-Only regression testing is needed.