You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

spring-boot-starter-webflux:3.0.5升级及依赖收敛错误求助

问题描述

Blackduck扫描检出一处高危漏洞,漏洞的传递依赖路径为:
org.springframework.boot:spring-boot-starter-webflux:jar:3.0.5 -> org.springframework.boot:spring-boot-starter-webflux:jar -> org.springframework.boot:spring-boot-starter-reactor-netty:jar -> netty-codec

注:已通过添加依赖将spring-boot-starter-webflux版本改为3.0.5。

根据短期修复建议,我在pom.xml中添加了netty-codec依赖,将其版本升级至4.1.90.Final,依赖代码如下:

<dependency>
    <groupId>io.netty</groupId>
    <artifactId>netty-codec</artifactId>
    <version>4.1.90.Final</version>
</dependency>

但此时触发了Maven Enforcer插件的错误:Some Enforcer rules have failed.,具体错误原因如下:

Dependency convergence error for org.springframework.boot:spring-boot-starter-reactor-netty:jar:2.6.9:compile paths to dependency are:

  +-org.springframework.boot:spring-boot-starter-webflux:jar:3.0.5:compile
    +-org.springframework.boot:spring-boot-starter-reactor-netty:jar:2.6.9:compile

恳请提供该问题的解决方案。

解决方案

方法1:统一spring-boot-starter-reactor-netty版本

错误核心是spring-boot-starter-webflux:3.0.5依赖了低版本的spring-boot-starter-reactor-netty:2.6.9,版本不匹配导致依赖收敛校验失败。直接在pom.xml中显式声明该依赖并指定与Spring Boot 3.0.5兼容的版本:

<dependency>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-reactor-netty</artifactId>
    <version>3.0.5</version>
</dependency>

该版本默认依赖的netty-codec通常会符合安全要求,若仍不满足,可保留之前显式声明的netty-codec版本。

方法2:通过dependencyManagement全局管控版本

无需直接添加依赖,在dependencyManagement节点中统一指定版本,强制项目所有依赖路径使用该版本:

<dependencyManagement>
    <dependencies>
        <dependency>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-starter-reactor-netty</artifactId>
            <version>3.0.5</version>
        </dependency>
        <!-- 同步管控netty-codec版本,确保全局生效 -->
        <dependency>
            <groupId>io.netty</groupId>
            <artifactId>netty-codec</artifactId>
            <version>4.1.90.Final</version>
        </dependency>
    </dependencies>
</dependencyManagement>

方法3:临时调整Maven Enforcer规则(不推荐)

若上述方法暂时无法落地,可临时修改Enforcer插件配置,忽略该依赖的收敛错误:

<build>
    <plugins>
        <plugin>
            <groupId>org.apache.maven.plugins</groupId>
            <artifactId>maven-enforcer-plugin</artifactId>
            <version>3.3.0</version>
            <executions>
                <execution>
                    <id>enforce-rules</id>
                    <goals>
                        <goal>enforce</goal>
                    </goals>
                    <configuration>
                        <rules>
                            <dependencyConvergence>
                                <excludes>
                                    <exclude>org.springframework.boot:spring-boot-starter-reactor-netty</exclude>
                                </excludes>
                            </dependencyConvergence>
                        </rules>
                    </configuration>
                </execution>
            </executions>
        </plugin>
    </plugins>
</build>

注意:此方法仅绕过错误,未解决根本的版本冲突,长期不建议使用。

内容的提问来源于stack exchange,提问作者RagaSGNur

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.27 00:15:19