File tree Expand file tree Collapse file tree
server/embedded/src/org/labkey/embedded Expand file tree Collapse file tree Original file line number Diff line number Diff line change 217217 <packageUrl regex =" true" >^pkg:maven/org\.itadaki/bzip2@.*$</packageUrl >
218218 <cve >CVE-2005-1260</cve >
219219 </suppress >
220+
221+ <!-- Related to the setting of channel binding as required, which is not relevant to us. -->
222+ <suppress >
223+ <notes ><![CDATA[
224+ file name: postgresql-42.7.4.jar
225+ ]]> </notes >
226+ <packageUrl regex =" true" >^pkg:maven/org\.postgresql/postgresql@.*$</packageUrl >
227+ <vulnerabilityName >CVE-2025-49146</vulnerabilityName >
228+ </suppress >
220229</suppressions >
Original file line number Diff line number Diff line change @@ -263,6 +263,7 @@ poiVersion=5.4.0
263263
264264pollingWatchVersion =0.2.0
265265
266+ # Newer versions of the driver have a perf degradation that's important for us. https://github.com/pgjdbc/pgjdbc/issues/3505
266267postgresqlDriverVersion =42.7.4
267268
268269quartzVersion =2.5.0
@@ -288,7 +289,7 @@ snappyJavaVersion=1.1.10.7
288289# Also, update apacheTomcatVersion above to match Spring Boot's Tomcat dependency version
289290springBootVersion =3.5.0
290291# This usually matches the Spring Framework version dictated by springBootVersion
291- springVersion =6.2.7
292+ springVersion =6.2.8
292293
293294sqliteJdbcVersion =3.49.1.0
294295
Original file line number Diff line number Diff line change 77import org .springframework .boot .autoconfigure .SpringBootApplication ;
88import org .springframework .boot .context .ApplicationPidFileWriter ;
99import org .springframework .boot .context .properties .ConfigurationProperties ;
10+ import org .springframework .boot .web .embedded .tomcat .TomcatConnectorCustomizer ;
1011import org .springframework .boot .web .embedded .tomcat .TomcatServletWebServerFactory ;
1112import org .springframework .boot .web .server .WebServerFactoryCustomizer ;
1213import org .springframework .context .annotation .Bean ;
@@ -82,11 +83,11 @@ public static void main(String[] args)
8283 String enforceCsp = baseCsp + """
8384 ${UPGRADE.INSECURE.REQUESTS}
8485 frame-ancestors 'self' ;
85- report-uri /admin-contentSecurityPolicyReport.api?cspVersion=e12&${CSP.REPORT.PARAMS} ;
86+ report-uri ${context.contextPath:} /admin-contentSecurityPolicyReport.api?cspVersion=e12&${CSP.REPORT.PARAMS} ;
8687 """ ;
8788 // Leave out upgrade_insecure_requests and frame-ancestors directives, since they produce warnings on some browsers
8889 String reportCsp = baseCsp + """
89- report-uri /admin-contentSecurityPolicyReport.api?cspVersion=r12&${CSP.REPORT.PARAMS} ;
90+ report-uri ${context.contextPath:} /admin-contentSecurityPolicyReport.api?cspVersion=r12&${CSP.REPORT.PARAMS} ;
9091 """ ;
9192 application .setDefaultProperties (Map .of (
9293 "server.tomcat.basedir" , "." ,
You can’t perform that action at this time.
0 commit comments