<commons-lang3.version>3.18.0</commons-lang3.version><!-- to fix CVE-2025-48924. TODO: remove when fixed in spring-boot-dependencies -->
<netty.version>4.1.134.Final</netty.version><!-- to fix CVE-2026-42579, CVE-2026-42583, CVE-2026-42584, CVE-2026-42587, and MQTT decoder regression introduced in 4.1.133 by the CVE-2026-44248 fix. TODO: remove when fixed in spring-boot-dependencies -->
<wire-schema.version>6.3.0</wire-schema.version><!-- to fix CVE-2026-45799 (transitive wire-runtime). TODO: remove pin when upstream bundles >= 6.3.0-->
<wire-schema.version>6.3.0</wire-schema.version><!-- to fix CVE-2026-45799 (transitive wire-runtime). Not managed by the Spring Boot BOM — this pin is the sole source of the wire version, nothing to defer to. TODO: remove only once a TB dependency pulls wire >= 6.3.0 transitively, making the explicit pin redundant.-->
<twilio.version>10.1.3</twilio.version>
<hypersistence-utils.version>3.7.4</hypersistence-utils.version><!-- artifact name should be updated with hibernate-core version -->