Skip to content

Conversation

loitly
Copy link
Contributor

@loitly loitly commented Oct 6, 2025

Ticket: https://jira.ipac.caltech.edu/browse/FIREFLY-1805
Additional changes here: https://github.com/IPAC-SW/irsa-ife/pull/441

  • Moved JOSSOAdapter and its dependencies to irsa-ife

We reduced the vulnerabilities from 13 critical and 25 high to 1 critical and 12 high.

The remaining critical issue originates from spring-jdbc, which is outdated and currently has no available fix. Upgrading it would require code changes to critical operations, so we may need to create a separate ticket and schedule it for a later phase.

Test:
https://firefly-1805-jar-security.irsakubedev.ipac.caltech.edu/irsaviewer/
https://fireflydev.ipac.caltech.edu/firefly-1805-jar-security/firefly/

-Only regression testing is needed.

@loitly loitly added this to the 2025.5 milestone Oct 6, 2025
@loitly loitly requested a review from robyww October 6, 2025 15:25
@loitly loitly self-assigned this Oct 6, 2025
@loitly loitly added the dependencies Pull requests that update a dependency file label Oct 6, 2025
@loitly loitly merged commit 93e7124 into dev Oct 8, 2025
@loitly loitly deleted the FIREFLY-1805-jar-security branch October 8, 2025 19:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants