v0.1.25.18 — drop tomcat override (SB 3.5.14 BOM-managed) + Jedis fleet alignment
[benchmark-skip]
Dependency hygiene release. No application-level code or wire-format changes — pom-only patch. Benchmark gate bypassed because a dep-only release exercises only environmental noise on the perf path (precedent: v0.1.25.9, .10, .11).
Changed
- Spring Boot 3.5.13 → 3.5.14. Patch upgrade picking up upstream security hardening (constant-time DevTools secret comparison,
RandomValuePropertySourceSecureRandom, consistent SSL hostname verification,ApplicationPidFileWriter/ApplicationTempsymlink fixes). - Drop
<tomcat.version>10.1.54</tomcat.version>override. SB 3.5.14's BOM now manages Tomcat 10.1.54 directly (verified againstspring-boot-dependencies-3.5.14.pom). The explicit pin from v0.1.25.16 (closing CVE-2026-34483 / CVE-2026-34487) is now redundant. - Jedis 7.4.1 → 6.2.0. Aligns with
cycles-server-events(6.2.0) andcycles-server-admin(6.2.0) on a single Redis-client major across the fleet, simplifying coordinated dependency upgrades. All 152 tests pass on 6.2.0. commons-lang3 3.18.0override retained — SB 3.5.14's BOM still manages 3.17.0 (CVE-2025-48924 unfixed there). Comment updated to reference SB 3.5.14.
See CHANGELOG.md for the full entry.
Fleet alignment
Matching releases: cycles-server-events v0.1.25.12, cycles-server-admin v0.1.25.41.