Backport Spring Framework 7.0.8 to 2.568.1 LTS
envgap__jenkinsci__jenkins-26901
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
8374115b093685acde9f07ccd950232f5ec9547b- Manifest
bom/pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
jenkinsci/jenkins #26901 · read the original issue
Spring Framework 7.0.8 was released 8 Jun 2026 with fixes for 18 CVEs. The [blog post](https://spring.io/blog/2026/06/01/spring_and_security_in_the_times_of_ai) says: > We highly recommend that all Spring users upgrade to the latest versions that are released in June to address the large number of security vulnerabilities that are being announced. While most CVEs are medium-to-low severity, the sheer volume of this release demands special attention. The Spring Framework 7.0.8 upgrade for Jenkins core is already in a [pull request](https://github.com/jenkinsci/jenkins/pull/26896) that has passed BOM and ATH. It is expected to release in Jenkins 2.569 June 16, 2026. I think we should backport Spring Framework 7.0.8 to Jenkins 2.568.1 so that we reduce the number of security reports from vulnerability scanners.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]