Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

In Optimize 7, exclude Spring beans dependency from process engine #5019

Open
1 task
yanavasileva opened this issue Mar 12, 2025 · 0 comments
Open
1 task
Labels
group:support All requests that are linked to a customer request. DRI: Tassilo potential:optimize 3.15.2 scope:optimize Changes to Optimize. type:task Issues that are a change to the project that is neither a feature nor a bug fix.

Comments

@yanavasileva
Copy link
Member

yanavasileva commented Mar 12, 2025

Context

  • Optimize 7 (3.12-3.15) has transitive dependency to Spring 5 via Camunda engine (7.20-7.22).
  • Spring 5 is end of life.
  • Optimize 7 doesn't use the Spring beans transitive dependency, it has its own dependency to Spring Framework 6.
  • Scanner reports of users detect the transitive dependencies as vulnerable.

Acceptance Criteria (Required on creation)

  • Exclude Spring beans dependency from Camunda 7 engine similar to feel engine and commons logging.

Hints

Links

Breakdown

Pull Requests

Preview Give feedback
No tasks being tracked yet.

Dev2QA handover

  • Does this ticket need a QA test and the testing goals are not clear from the description? Add a Dev2QA handover comment
@yanavasileva yanavasileva added group:support All requests that are linked to a customer request. DRI: Tassilo scope:optimize Changes to Optimize. type:task Issues that are a change to the project that is neither a feature nor a bug fix. labels Mar 12, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
group:support All requests that are linked to a customer request. DRI: Tassilo potential:optimize 3.15.2 scope:optimize Changes to Optimize. type:task Issues that are a change to the project that is neither a feature nor a bug fix.
Projects
None yet
Development

No branches or pull requests

2 participants