Skip to content

INS-1584#162

Merged
amattu2 merged 6 commits into3.3.0from
INS-1584
Mar 23, 2026
Merged

INS-1584#162
amattu2 merged 6 commits into3.3.0from
INS-1584

Conversation

@JoonLeeNIH
Copy link
Copy Markdown
Contributor

Overview

Vulnerability fixes

Change Details (Specifics)

Updated Tomcat base image in Dockerfile. Updated Maven dependencies in pom.xml

Related Ticket(s)

https://tracker.nci.nih.gov/browse/INS-1584

Copilot AI review requested due to automatic review settings March 23, 2026 19:57
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR focuses on vulnerability remediation by updating the runtime Tomcat version used in the container image and bumping several Maven-managed dependency versions.

Changes:

  • Updated the Tomcat base image version used in the production Docker stage.
  • Updated dependency versions in pom.xml, including Spring Framework override, Log4j, and embedded Tomcat.
  • Added a Jackson BOM import to dependency management.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 2 comments.

File Description
pom.xml Updates key dependency versions and imports Jackson BOM for vulnerability remediation.
Dockerfile Bumps the Tomcat production base image to a newer patch release.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@JoonLeeNIH JoonLeeNIH temporarily deployed to ccdi-manager-nonprod March 23, 2026 20:20 — with GitHub Actions Inactive
@JoonLeeNIH JoonLeeNIH requested a review from amattu2 March 23, 2026 20:23
@amattu2 amattu2 added this to the 3.3.0 milestone Mar 23, 2026
@amattu2 amattu2 merged commit 15d483b into 3.3.0 Mar 23, 2026
3 of 4 checks passed
@amattu2 amattu2 deleted the INS-1584 branch March 23, 2026 20:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants