Skip to content

Conversation

@bigcyy
Copy link
Member

@bigcyy bigcyy commented Mar 21, 2025

  • I have registered the PR changes.

Ⅰ. Describe what this PR did

upgrade tomcat-embed-core to 9.0.99 to fix CVE-2025-24813

Ⅱ. Does this pull request fix one issue?

fiexs #7240

Ⅲ. Why don't you add test cases (unit test/integration test)?

Ⅳ. Describe how to verify it

Ⅴ. Special notes for reviews

@funky-eyes funky-eyes added first-time contributor first-time contributor dependencies Pull requests that update a dependency file labels Mar 22, 2025
@funky-eyes funky-eyes added this to the 2.4.0 milestone Mar 22, 2025
Copy link
Contributor

@funky-eyes funky-eyes left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@bigcyy
Copy link
Member Author

bigcyy commented Mar 22, 2025

ok, I have registered the PR changes.

@codecov
Copy link

codecov bot commented Mar 22, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 53.99%. Comparing base (68460b8) to head (c58d99e).
Report is 2 commits behind head on 2.x.

Additional details and impacted files
@@            Coverage Diff            @@
##                2.x    #7241   +/-   ##
=========================================
  Coverage     53.98%   53.99%           
- Complexity     7203     7204    +1     
=========================================
  Files          1173     1173           
  Lines         41792    41796    +4     
  Branches       4905     4906    +1     
=========================================
+ Hits          22561    22567    +6     
+ Misses        17099    17097    -2     
  Partials       2132     2132           

see 6 files with indirect coverage changes

Impacted file tree graph

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@slievrly slievrly changed the title bugfix: upgrade tomcat-embed-core to 9.0.99 to fix CVE-2025-24813 bugfix: upgrade tomcat-embed-core to 9.0.99 Mar 22, 2025
@slievrly slievrly changed the title bugfix: upgrade tomcat-embed-core to 9.0.99 optimize: upgrade tomcat-embed-core to 9.0.99 Mar 22, 2025
Copy link
Member

@slievrly slievrly left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@slievrly slievrly merged commit 13509de into apache:2.x Mar 23, 2025
9 checks passed
slievrly pushed a commit to slievrly/fescar that referenced this pull request Oct 21, 2025
YvCeung pushed a commit to YvCeung/incubator-seata that referenced this pull request Dec 25, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file first-time contributor first-time contributor

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants