Skip to content

Commit 11cac2a

Browse files
CodeCasterXclaude
andcommitted
fix(fit): 升级 AssertJ 到 3.27.7 修复 XXE 安全漏洞
升级 org.assertj:assertj-core 依赖版本以修复安全漏洞: - 将 assertj.version 从 3.27.3 升级到 3.27.7 - 修复 CVE-2026-24400 XML 外部实体注入漏洞 - 漏洞影响 isXmlEqualTo 方法,但项目未使用该方法 - 仅测试依赖,实际风险低,升级无破坏性变更 参考: GHSA-rqfh-9r24-8c9r 关闭 Dependabot 告警 #24 Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
1 parent 7d3e9d8 commit 11cac2a

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

framework/dependency/pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@
6363
<mybatis.version>3.5.19</mybatis.version>
6464

6565
<!-- Test framework versions -->
66-
<assertj.version>3.27.3</assertj.version>
66+
<assertj.version>3.27.7</assertj.version>
6767
<junit5.version>5.12.2</junit5.version>
6868
<mockito.version>5.17.0</mockito.version>
6969
<h2.version>2.3.232</h2.version>

0 commit comments

Comments
 (0)