Skip to content

Conversation

@aurbroszniowski
Copy link
Contributor

@aurbroszniowski aurbroszniowski commented Jan 23, 2026

  • Removed Gretty and used an embedded jetty 12 instance instead - See EmbeddedPeeperServer
  • Moved to jakarta
  • Moved from SpotBug 4.2.3 to 4.5.8
    because of CVE (commons-text:1.9 and gson:2.8.6)

Note about the Mend report: the following vulnerable dependencies aren’t coming from the demos module:

Unknown
k8s.io/apimachinery:v0.24.2

CheckStyle 8.45.1
commons-beanutils:1.9.3

@Gen-SIQA-User
Copy link
Collaborator

Gen-SIQA-User commented Jan 23, 2026

No vulnerabilities found.

@aurbroszniowski aurbroszniowski force-pushed the TDB-19854-upgrade-dependencies-main branch 2 times, most recently from 095df7b to 6cf2004 Compare January 26, 2026 12:09
@aurbroszniowski aurbroszniowski force-pushed the TDB-19854-upgrade-dependencies-main branch from 6cf2004 to 18d2def Compare January 26, 2026 13:06
@Gen-SIQA-User
Copy link
Collaborator

Checks Summary

Last run: 2026-01-26T20:38:05.238Z

Code Risk Analyzer vulnerability scan found 2 vulnerabilities:

Severity Identifier Package Details Fix
◻ Unknown CVE-2026-1225 ch.qos.logback:logback-core
Logback allows an attacker to instantiate classes already present on the class pathGHSA-qqpg-mvqg-649v

ch.qos.logback:logback-core:1.5.20->ch.qos.logback:logback-classic:1.5.20,org.terracotta:server-api:5.12.15,org.terracotta:galvan:5.12.15,org.terracotta.internal:galvan-support:5.12.15,org.terracotta:terracotta-dynamic-config-testing-galvan:5.11.6
1.5.25
◻ Unknown CVE-2025-68161 org.apache.logging.log4j:log4j-core
Apache Log4j does not verify the TLS hostname in its Socket AppenderGHSA-vc5p-v9hr-52mj

org.apache.logging.log4j:log4j-core:2.25.2->com.github.spotbugs:spotbugs:4.9.8,org.apache.logging.log4j:log4j-core:2.25.2,com.github.spotbugs:spotbugs-annotations:4.9.8,com.github.spotbugs:spotbugs:4.9.8
2.25.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants