From ce0d27e3f08c1d0927f97a93a51f7a6c7b661e40 Mon Sep 17 00:00:00 2001 From: "aikido-autofix[bot]" <119856028+aikido-autofix[bot]@users.noreply.github.com> Date: Tue, 9 Jun 2026 22:56:07 +0000 Subject: [PATCH] fix(security): update dependencies --- agent/build.gradle | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/agent/build.gradle b/agent/build.gradle index d6656bf92..da93b03cd 100644 --- a/agent/build.gradle +++ b/agent/build.gradle @@ -11,7 +11,20 @@ dependencies { compileOnly 'javax.servlet:javax.servlet-api:4.0.1' // spring 2 -> javax compileOnly 'io.projectreactor.netty:reactor-netty-http:1.2.1' // For Spring Webflux compileOnly 'io.javalin:javalin:6.4.0' - compileOnly 'org.springframework:spring-web:5.3.20' + compileOnly 'org.springframework:spring-web:6.2.11' + + // Version constraints for transitive dependencies + constraints { + implementation 'org.springframework:spring-core:6.2.11' + implementation 'org.springframework:spring-webmvc:6.2.11' + implementation 'org.springframework:spring-beans:6.2.11' + implementation 'org.springframework:spring-expression:6.2.11' + implementation 'org.springframework:spring-context:6.2.11' + implementation 'org.eclipse.jetty:jetty-server:12.0.33' + implementation 'org.eclipse.jetty:jetty-http:12.0.33' + implementation 'io.netty:netty-handler:4.1.135.Final' + implementation 'io.netty:netty-codec-http2:4.1.135.Final' + } } shadowJar {