← All tasks
javajenkinsci/jenkins #26901Not a task: not reproduced

Backport Spring Framework 7.0.8 to 2.568.1 LTS

envgap__jenkinsci__jenkins-26901

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
8374115b093685acde9f07ccd950232f5ec9547b
Manifest
bom/pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

jenkinsci/jenkins #26901 · read the original issue
Spring Framework 7.0.8 was released 8 Jun 2026 with fixes for 18 CVEs.  The [blog post](https://spring.io/blog/2026/06/01/spring_and_security_in_the_times_of_ai) says:

> We highly recommend that all Spring users upgrade to the latest versions that are released in June to address the large number of security vulnerabilities that are being announced. While most CVEs are medium-to-low severity, the sheer volume of this release demands special attention.

The Spring Framework 7.0.8 upgrade for Jenkins core is already in a [pull request](https://github.com/jenkinsci/jenkins/pull/26896) that has passed BOM and ATH.  It is expected to release in Jenkins 2.569 June 16, 2026.

I think we should backport Spring Framework 7.0.8 to Jenkins 2.568.1 so that we reduce the number of security reports from vulnerability scanners.
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]