diff --git a/CLAUDE.md b/CLAUDE.md
index e299d7f..e61d610 100644
--- a/CLAUDE.md
+++ b/CLAUDE.md
@@ -20,6 +20,15 @@ module is **`bridged`**. Always pass these to IDE MCP tools:
test run). A per-file-clean file can still break the build or another module. This is the
whole-project gate before declaring work done or committing.
+**Whenever dependencies change (or a `pom.xml` edit), validate CVEs with
+`jetbrains get_file_problems{filePath: "bridged/pom.xml"}`** — its Mend.io check reflects the
+dependencies on disk. (Note: `ide_diagnostics` / intellij-index does NOT re-resolve dependencies
+after a pom edit without a full Maven reimport, so it reports stale CVE results — don't trust it
+for this.) Treat a CVE warning like any other: bump to a patched version and confirm
+`mvn clean install` still passes. If the latest available version is still flagged (EOL line,
+"insufficient information", or config-file-only advisories), document it as accepted in the pom
+rather than chasing a fix that doesn't exist.
+
### Use IDE MCP tools for navigation, refactoring, and diagnostics only
- **Navigate (prefer over Grep/Read for symbols):** `ide_find_definition`, `ide_find_class`,
diff --git a/bridged/pom.xml b/bridged/pom.xml
index 7ac7529..b9f585f 100644
--- a/bridged/pom.xml
+++ b/bridged/pom.xml
@@ -17,13 +17,40 @@
UTF-8
dev.ltms.bridged.Bridged
- 2.18.2
- 6.3.0
+ 2.19.0
+ 6.7.0
+ 11.0.25
2.0.16
- 1.5.15
+ 1.5.18
5.11.4
+
+
+
+
+
+
+ org.eclipse.jetty
+ jetty-bom
+ ${jetty.version}
+ pom
+ import
+
+
+
+
@@ -116,7 +143,7 @@
contract
-
+