Skip to content

fix(deps): update dependency org.apache.tomcat.embed:tomcat-embed-core to v10.1.55 [security] - #31

Open
alaudaa-renovate[bot] wants to merge 1 commit into
alauda-2025.1.0from
renovate/patch-org.apache.tomcat.embed-10.1.42
Open

fix(deps): update dependency org.apache.tomcat.embed:tomcat-embed-core to v10.1.55 [security]#31
alaudaa-renovate[bot] wants to merge 1 commit into
alauda-2025.1.0from
renovate/patch-org.apache.tomcat.embed-10.1.42

Conversation

@alaudaa-renovate

@alaudaa-renovate alaudaa-renovate Bot commented Nov 21, 2025

Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Confidence
org.apache.tomcat.embed:tomcat-embed-core 10.1.42 -> 10.1.55 age confidence

Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams

BIT-tomcat-2025-53506 / CVE-2025-53506 / GHSA-25xr-qj8w-c4vf

More information

Details

Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100.

Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits

BIT-tomcat-2025-52520 / CVE-2025-52520 / GHSA-wr62-c79q-cv37

More information

Details

For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected.

Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat Improper Resource Shutdown or Release vulnerability

BIT-tomcat-2025-48989 / CVE-2025-48989 / GHSA-gqp3-2cvr-x8m3

More information

Details

Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected.

Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat Vulnerable to Relative Path Traversal

BIT-tomcat-2025-55752 / CVE-2025-55752 / GHSA-wmwf-9ccg-fff5

More information

Details

The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for /WEB-INF/ and /META-INF/. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.0.M11 through 9.0.108.

The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.6 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences

BIT-tomcat-2025-55754 / CVE-2025-55754 / GHSA-vfww-5hm6-hx2j

More information

Details

Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.10, from 10.1.0-M1 through 10.1.44, from 9.0.40 through 9.0.108.

The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.60 though 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.11 or later, 10.1.45 or later or 9.0.109 or later, which fix the issue.

Severity

  • CVSS Score: 9.6 / 10 (Critical)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat Vulnerable to Improper Resource Shutdown or Release

BIT-tomcat-2025-61795 / CVE-2025-61795 / GHSA-hgrr-935x-pq79

More information

Details

If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.11, from 10.1.0-M1 through 10.1.46, from 9.0.0.M1 through 9.0.109.

The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.12 or later, 10.1.47 or later or 9.0.110 or later which fixes the issue.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat - Client certificate verification bypass

BIT-tomcat-2025-66614 / CVE-2025-66614 / GHSA-fpj8-gq4v-p354

More information

Details

Improper Input Validation vulnerability.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112.

The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field.

The vulnerability only applies if client certificate authentication is only enforced at the Connector. It does not apply if client certificate authentication is enforced at the web application.

Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fix the issue.

Severity

  • CVSS Score: 9.1 / 10 (Critical)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat has an Improper Input Validation vulnerability

BIT-tomcat-2026-24734 / CVE-2026-24734 / GHSA-mgp5-rv84-w37q

More information

Details

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat.

When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed.

This issue affects Apache Tomcat Native:  from 1.3.0 through 1.3.4, from 2.0.0 through 2.0.11; Apache Tomcat: from 11.0.0-M1 through 11.0.17, from 10.1.0-M7 through 10.1.51, from 9.0.83 through 9.0.114.

The following versions were EOL at the time the CVE was created but are
known to be affected: from 1.1.23 through 1.1.34, from 1.2.0 through 1.2.39. Older EOL versions are not affected.

Apache Tomcat Native users are recommended to upgrade to versions 1.3.5 or later or 2.0.12 or later, which fix the issue.

Apache Tomcat users are recommended to upgrade to versions 11.0.18 or later, 10.1.52 or later or 9.0.115 or later which fix the issue.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat has an HTTP Request/Response Smuggling vulnerability

BIT-tomcat-2026-24880 / CVE-2026-24880 / GHSA-563x-q5rq-57qp

More information

Details

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Other, unsupported versions may also be affected.

Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat has an Open Redirect vulnerability

BIT-tomcat-2026-25854 / CVE-2026-25854 / GHSA-9m3c-qcxr-9x87

More information

Details

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100.
Other, unsupported versions may also be affected

Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

Severity

  • CVSS Score: 6.1 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve

BIT-tomcat-2026-34483 / CVE-2026-34483 / GHSA-rv64-5gf8-9qq8

More information

Details

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File

BIT-tomcat-2026-34487 / CVE-2026-34487 / GHSA-x4m4-345f-5h5g

More information

Details

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.

Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat - AJP secret compared in non-constant time

BIT-tomcat-2026-43514 / CVE-2026-43514 / GHSA-9m89-8frq-c98c

More information

Details

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.21
Apache Tomcat 10.1.0-M1 to 10.1.54
Apache Tomcat 9.0.0.M1 to 9.0.117
Older, unsupported versions may also be affected

Description:
The AJP secret was compared in non-constant time allowing an attacker on
the local network to mount a timing attack to determine the AJP secret.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:

  • Upgrade to Apache Tomcat 11.0.22 or later
  • Upgrade to Apache Tomcat 10.1.55 or later
  • Upgrade to Apache Tomcat 9.0.118 or later

Severity

  • CVSS Score: 3.7 / 10 (Low)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat: LockOutRealm treats user names as case-sensitive

BIT-tomcat-2026-43513 / CVE-2026-43513 / GHSA-5mp6-jrq3-r938

More information

Details

Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Older unsupported versions may also be affected.

Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat - HTTP/2 request headers not validated

BIT-tomcat-2026-41293 / CVE-2026-41293 / GHSA-r29c-68gh-xp6x

More information

Details

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.21
Apache Tomcat 10.1.0-M1 to 10.1.54
Apache Tomcat 9.0.0.M1 to 9.0.117
Older, unsupported versions may also be affected

Description:
HTTP/2 request headers were not validated which may have triggered
unexpected application behaviour if the application (quite reasonably)
assumed that header value exposed through the Servlet API would be
specification compliant.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:

  • Upgrade to Apache Tomcat 11.0.22 or later
  • Upgrade to Apache Tomcat 10.1.55 or later
  • Upgrade to Apache Tomcat 9.0.118 or later

Credit:
This issue was identified by Dawit Jeong (@​dawitngoliath)

Severity

  • CVSS Score: 9.8 / 10 (Critical)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat - WebSocket authentication header exposure

BIT-tomcat-2026-42498 / CVE-2026-42498 / GHSA-fv25-8xcx-gqjc

More information

Details

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.21
Apache Tomcat 10.1.0-M1 to 10.1.54
Apache Tomcat 9.0.2 to 9.0.117
Older, unsupported versions may also be affected

Description:
If a WebSocket request was redirected after authentication, Tomcat's
WebSocket client would present the most recent authentication header to
the redirect target host.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:

  • Upgrade to Apache Tomcat 11.0.22 or later
  • Upgrade to Apache Tomcat 10.1.55 or later
  • Upgrade to Apache Tomcat 9.0.118 or later

Credit:
This issue was identified by lokerxx

Severity

  • CVSS Score: 7.3 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

BIT-tomcat-2026-41284 / CVE-2026-41284 / GHSA-gx5v-xp9w-j4cg

More information

Details

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.21
Apache Tomcat 10.1.0-M1 to 10.1.54
Apache Tomcat 9.0.0.M1 to 9.0.117
Older, unsupported versions may also be affected

Description:
No limit was enforced on the request body for WebDAV LOCK or PROPFIND
requests which were available to unauthenticated users.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:

  • Upgrade to Apache Tomcat 11.0.22 or later
  • Upgrade to Apache Tomcat 10.1.55 or later
  • Upgrade to Apache Tomcat 9.0.118 or later

Credit:
This issue was identified by Dariusz Gońda

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat - Digest authenticator will authenticate any unknown user

BIT-tomcat-2026-43512 / CVE-2026-43512 / GHSA-h6fc-48rj-7qqh

More information

Details

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.21
Apache Tomcat 10.1.0-M1 to 10.1.54
Apache Tomcat 9.0.0.M1 to 9.0.117
Older, unsupported versions may also be affected

Description:
When DIGEST authentication was configured, any user not known to the
configured Realm would be authenticated if they presented the password
"null".

Mitigation:
Users of the affected versions should apply one of the following
mitigations:

  • Upgrade to Apache Tomcat 11.0.22 or later
  • Upgrade to Apache Tomcat 10.1.55 or later
  • Upgrade to Apache Tomcat 9.0.118 or later

Severity

  • CVSS Score: 9.8 / 10 (Critical)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Apache Tomcat - Security constraints not correctly applied

BIT-tomcat-2026-43515 / CVE-2026-43515 / GHSA-5m62-pw8w-7w9f

More information

Details

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.21
Apache Tomcat 10.1.0-M1 to 10.1.54
Apache Tomcat 9.0.0.M1 to 9.0.117
Older, unsupported versions may also be affected

Description:
When multiple security constraints defined an HTTP method constraint for
the same extension pattern, only the first method constraint was applied.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:

  • Upgrade to Apache Tomcat 11.0.22 or later
  • Upgrade to Apache Tomcat 10.1.55 or later
  • Upgrade to Apache Tomcat 9.0.118 or later

Severity

  • CVSS Score: 9.1 / 10 (Critical)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Configuration

📅 Schedule: Branch creation - "" in timezone Asia/Shanghai, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@alaudabot

Copy link
Copy Markdown

🚨 Stale Pull Request Warning

This pull request has been inactive for 34 days.

Automated Actions Schedule:

  • ⚠️ Warning: After 30 days (now)
  • 🔒 Auto-close: After 60 days
  • 🗑️ Branch deletion: After 90 days (if not protected)

To keep this PR active:

  • Add new commits
  • Reply to this comment
  • Request reviews

Protected branches (won't be deleted): main,release-*,alauda-*

This is an automated message. Reply to this comment to reset the inactivity timer.

@alaudaa-renovate
alaudaa-renovate Bot force-pushed the renovate/patch-org.apache.tomcat.embed-10.1.42 branch from 3495d74 to ad2abd7 Compare March 19, 2026 13:50
@alaudaa-renovate alaudaa-renovate Bot changed the title fix(deps): update dependency org.apache.tomcat.embed:tomcat-embed-core to v10.1.47 [security] fix(deps): update dependency org.apache.tomcat.embed:tomcat-embed-core to v10.1.50 [security] Mar 19, 2026
@alaudaa-renovate
alaudaa-renovate Bot force-pushed the renovate/patch-org.apache.tomcat.embed-10.1.42 branch from ad2abd7 to 17f20de Compare April 9, 2026 18:35
@alaudaa-renovate alaudaa-renovate Bot changed the title fix(deps): update dependency org.apache.tomcat.embed:tomcat-embed-core to v10.1.50 [security] fix(deps): update dependency org.apache.tomcat.embed:tomcat-embed-core to v10.1.52 [security] Apr 9, 2026
@danielfbm

Copy link
Copy Markdown

PR Assist Bot — Owner Approval Needed

This PR targets release branch alauda-2025.1.0. Per policy, release-branch merges require explicit owner approval before the bot proceeds.

PR: AlaudaDevops/docker-sonarqube#31
Branch: alauda-2025.1.0
Type: Security / Dependency update (Renovate)

Please reply with /approve-merge or provide explicit approval for the bot to merge this PR on the next sweep.

@alaudabot

Copy link
Copy Markdown

[pr-assist-bot] Release Branch Security PR — Owner Approval Needed

This PR targets release branch alauda-2025.1.0. Per policy, release-branch dependency merges require explicit owner approval before the bot proceeds.

PR: #31 — fix(deps): update dependency org.apache.tomcat.embed:tomcat-embed-core to v10.1.52 [security]
Branch: alauda-2025.1.0
Type: Security / Dependency update (Renovate)

Please reply with /approve-merge or provide explicit approval for the bot to merge this PR on the next sweep.

@alaudabot

Copy link
Copy Markdown

PR Assist Bot Analysis

Status: All CI checks passing, owner approval received (/approve-merge).
Blocked by: Branch protection policy requires a GitHub approving review (not just a PR comment).
Action needed: A maintainer with write access must submit an approving review via GitHub's review UI for auto-merge to proceed.

@alaudaa-renovate
alaudaa-renovate Bot force-pushed the renovate/patch-org.apache.tomcat.embed-10.1.42 branch from 17f20de to c63bf3e Compare April 29, 2026 02:28
@alaudaa-renovate alaudaa-renovate Bot changed the title fix(deps): update dependency org.apache.tomcat.embed:tomcat-embed-core to v10.1.52 [security] fix(deps): update dependency org.apache.tomcat.embed:tomcat-embed-core to v10.1.54 [security] Apr 29, 2026
@alaudaa-renovate
alaudaa-renovate Bot force-pushed the renovate/patch-org.apache.tomcat.embed-10.1.42 branch from c63bf3e to bc67216 Compare May 20, 2026 00:35
@alaudaa-renovate alaudaa-renovate Bot changed the title fix(deps): update dependency org.apache.tomcat.embed:tomcat-embed-core to v10.1.54 [security] fix(deps): update dependency org.apache.tomcat.embed:tomcat-embed-core to v10.1.55 [security] May 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants