Skip to content

fix(QTDI-2863): bump tomcat to 9.0.118#1240

Open
undx wants to merge 1 commit into
masterfrom
ouf/QTDI-2863-cve-tomcat
Open

fix(QTDI-2863): bump tomcat to 9.0.118#1240
undx wants to merge 1 commit into
masterfrom
ouf/QTDI-2863-cve-tomcat

Conversation

@undx

@undx undx commented Jun 9, 2026

Copy link
Copy Markdown
Member

Requirements

  • Any code change adding any logic MUST be tested through a unit test executed with the default build
  • Any API addition MUST be done with a documentation update if relevant

Why this PR is needed?

QTDI-2863 : CVE-2026-41293|CVE-2026-43512|CVE-2026-43515 org.apache.tomcat:tomcat-catalina 9.0.117

What does this PR adds (design/code thoughts)?

AI generated code

https://internal.qlik.dev/general/ways-of-working/code-reviews/#guidelines-for-ai-generated-code

  • [] this PR has been written with the help of GitHub Copilot or another generative AI tool

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the project’s Apache Tomcat dependency version to address the CVEs referenced in QTDI-2863 by bumping org.apache.tomcat:* artifacts managed via the root Maven property.

Changes:

  • Bump tomcat.version from 9.0.117 to 9.0.118 in the root pom.xml.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@sonar-rnd

sonar-rnd Bot commented Jun 9, 2026

Copy link
Copy Markdown

@undx undx changed the title chore(QTDI-2863): bump tomcat to 9.0.118 fix(QTDI-2863): bump tomcat to 9.0.118 Jun 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants