Skip to content

chore(deps): pin HttpComponents 5 versions used by WireMock tests - #2655

Closed
phipag wants to merge 1 commit into
mainfrom
chore/wiremock-httpclient5-pins
Closed

phipag wants to merge 1 commit into
mainfrom
chore/wiremock-httpclient5-pins

Conversation

@phipag

@phipag phipag commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Summary

Changes

Pins httpclient5 5.6.4 and httpcore5/httpcore5-h2 5.4.4 in the root dependencyManagement. WireMock 3.13.2 resolves vulnerable 5.5.1 and 5.3.6 in the powertools-cloudformation and powertools-lambda-metadata tests. This clears 6 Dependabot alerts.

The pins carry no scope, so modules that use these libraries through the AWS SDK keep their existing scope. mvn verify passes on both modules.

Issue number: closes #2649


By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

Disclaimer: We value your time and bandwidth. As such, any pull requests created on non-triaged issues might not be successful.

@sonarqubecloud

sonarqubecloud Bot commented Oct 6, 2026

Copy link
Copy Markdown

@phipag

phipag commented Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #2597. Dropping Java 11 support allows a WireMock upgrade that fixes all WireMock alerts.

@phipag phipag closed this Oct 6, 2026
@phipag
phipag deleted the chore/wiremock-httpclient5-pins branch October 6, 2026 11:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Maintenance: pin HttpComponents 5 versions used by WireMock tests

1 participant