Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What changes did you make? (Give an overview)
My team suggested to replace kafdrop by kafka-ui, but I saw that your last release is 3 months old and therefore contains critical and high security findings.
So I updated all versions where possible without breaking changes, now trivy shows no critical or high findings anymore.
Those updates which would require additional work from my experience I just commented in the POMs without actually changing the version.
Is there anything you'd like reviewers to focus on?
If you remember a dependency where updating a minor revision broke something, then review those dependencies more carefully or maybe add a test if possible.
If you can, please enable dependabot/renovate where possible, staying up-to-date is the least amount of work and security bugs from my experience.
Updating is much easier if every version number is moved to an individual property:
mvn versions:display-property-updates
How Has This Been Tested? (put an "x" (case-sensitive!) next to an item)
Checklist (put an "x" (case-sensitive!) next to all the items, otherwise the build will fail)
Check out Contributing and Code of Conduct
A picture of a cute animal (not mandatory but encouraged)