spring-boot-starter-webflux:3.0.5升级及依赖收敛错误求助
Blackduck扫描检出一处高危漏洞,漏洞的传递依赖路径为:org.springframework.boot:spring-boot-starter-webflux:jar:3.0.5 -> org.springframework.boot:spring-boot-starter-webflux:jar -> org.springframework.boot:spring-boot-starter-reactor-netty:jar -> netty-codec
注:已通过添加依赖将spring-boot-starter-webflux版本改为3.0.5。
根据短期修复建议,我在pom.xml中添加了netty-codec依赖,将其版本升级至4.1.90.Final,依赖代码如下:
<dependency> <groupId>io.netty</groupId> <artifactId>netty-codec</artifactId> <version>4.1.90.Final</version> </dependency>
但此时触发了Maven Enforcer插件的错误:Some Enforcer rules have failed.,具体错误原因如下:
Dependency convergence error for org.springframework.boot:spring-boot-starter-reactor-netty:jar:2.6.9:compile paths to dependency are: +-org.springframework.boot:spring-boot-starter-webflux:jar:3.0.5:compile +-org.springframework.boot:spring-boot-starter-reactor-netty:jar:2.6.9:compile
恳请提供该问题的解决方案。
方法1:统一spring-boot-starter-reactor-netty版本
错误核心是spring-boot-starter-webflux:3.0.5依赖了低版本的spring-boot-starter-reactor-netty:2.6.9,版本不匹配导致依赖收敛校验失败。直接在pom.xml中显式声明该依赖并指定与Spring Boot 3.0.5兼容的版本:
<dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-reactor-netty</artifactId> <version>3.0.5</version> </dependency>
该版本默认依赖的netty-codec通常会符合安全要求,若仍不满足,可保留之前显式声明的netty-codec版本。
方法2:通过dependencyManagement全局管控版本
无需直接添加依赖,在dependencyManagement节点中统一指定版本,强制项目所有依赖路径使用该版本:
<dependencyManagement> <dependencies> <dependency> <groupId>org.springframework.boot</groupId> <artifactId>spring-boot-starter-reactor-netty</artifactId> <version>3.0.5</version> </dependency> <!-- 同步管控netty-codec版本,确保全局生效 --> <dependency> <groupId>io.netty</groupId> <artifactId>netty-codec</artifactId> <version>4.1.90.Final</version> </dependency> </dependencies> </dependencyManagement>
方法3:临时调整Maven Enforcer规则(不推荐)
若上述方法暂时无法落地,可临时修改Enforcer插件配置,忽略该依赖的收敛错误:
<build> <plugins> <plugin> <groupId>org.apache.maven.plugins</groupId> <artifactId>maven-enforcer-plugin</artifactId> <version>3.3.0</version> <executions> <execution> <id>enforce-rules</id> <goals> <goal>enforce</goal> </goals> <configuration> <rules> <dependencyConvergence> <excludes> <exclude>org.springframework.boot:spring-boot-starter-reactor-netty</exclude> </excludes> </dependencyConvergence> </rules> </configuration> </execution> </executions> </plugin> </plugins> </build>
注意:此方法仅绕过错误,未解决根本的版本冲突,长期不建议使用。
内容的提问来源于stack exchange,提问作者RagaSGNur

