Commit 11cac2a
fix(fit): 升级 AssertJ 到 3.27.7 修复 XXE 安全漏洞
升级 org.assertj:assertj-core 依赖版本以修复安全漏洞:
- 将 assertj.version 从 3.27.3 升级到 3.27.7
- 修复 CVE-2026-24400 XML 外部实体注入漏洞
- 漏洞影响 isXmlEqualTo 方法,但项目未使用该方法
- 仅测试依赖,实际风险低,升级无破坏性变更
参考: GHSA-rqfh-9r24-8c9r
关闭 Dependabot 告警 #24
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>1 parent 7d3e9d8 commit 11cac2a
1 file changed
+1
-1
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
63 | 63 | | |
64 | 64 | | |
65 | 65 | | |
66 | | - | |
| 66 | + | |
67 | 67 | | |
68 | 68 | | |
69 | 69 | | |
| |||
0 commit comments