diff --git a/CLAUDE.md b/CLAUDE.md index e299d7f..e61d610 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -20,6 +20,15 @@ module is **`bridged`**. Always pass these to IDE MCP tools: test run). A per-file-clean file can still break the build or another module. This is the whole-project gate before declaring work done or committing. +**Whenever dependencies change (or a `pom.xml` edit), validate CVEs with +`jetbrains get_file_problems{filePath: "bridged/pom.xml"}`** — its Mend.io check reflects the +dependencies on disk. (Note: `ide_diagnostics` / intellij-index does NOT re-resolve dependencies +after a pom edit without a full Maven reimport, so it reports stale CVE results — don't trust it +for this.) Treat a CVE warning like any other: bump to a patched version and confirm +`mvn clean install` still passes. If the latest available version is still flagged (EOL line, +"insufficient information", or config-file-only advisories), document it as accepted in the pom +rather than chasing a fix that doesn't exist. + ### Use IDE MCP tools for navigation, refactoring, and diagnostics only - **Navigate (prefer over Grep/Read for symbols):** `ide_find_definition`, `ide_find_class`, diff --git a/bridged/pom.xml b/bridged/pom.xml index 7ac7529..b9f585f 100644 --- a/bridged/pom.xml +++ b/bridged/pom.xml @@ -17,13 +17,40 @@ UTF-8 dev.ltms.bridged.Bridged - 2.18.2 - 6.3.0 + 2.19.0 + 6.7.0 + 11.0.25 2.0.16 - 1.5.15 + 1.5.18 5.11.4 + + + + + + + org.eclipse.jetty + jetty-bom + ${jetty.version} + pom + import + + + + @@ -116,7 +143,7 @@ contract - +