Hello Spring Boot Maintainers
As the title, I know that you have a semi-automated process
to upgrade dependencies, but in the 2.3.x branch, nothing has changed in these two weeks.
So I open the PR for upgrade the tomcat dependency to fix the vulnerability of tomcat. If you can perform these change, just upgrade in your way.
Thanks, have a nice day :)
Comment From: wilkinsona
Thanks, but our semi-automated process will pick up the latest version of Tomcat that’s available when we perform the next 2.3.x release in March.