• Andy Wilkinson's avatar
    Upgrade to Groovy 2.4.4 · 9b6538d5
    Andy Wilkinson authored
    Typically, a Spring Boot maintenance release would not move to a new
    minor version of a dependency. However there is a security
    vulnerability in Groovy [1] and 2.4.4 is the only release which
    contains a fix for it.
    
    The commit upgrades to 2.4.4, thereby ensuring that users of Groovy
    are not vulnerable by default. Users of Groovy whose applications are
    not affected by the vulnerability may choose to downgrade back to
    2.3.11 by overriding Spring Boot's dependency management.
    
    Closes gh-3540
    
    [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3253
    9b6538d5
Name
Last commit
Last update
..
pom.xml Loading commit data...