Story #16914: update dependencies to remediate known CVEs - #119
Merged
Merged
Conversation
Bump direct dependencies and pin the vulnerable transitive ones so that a single patched version is resolved across every module and inside the shaded jars. Direct dependencies (parent properties): - jackson 2.18.3 -> 2.22.3 (7 CVEs in databind, 2 in core) - logback 1.5.18 -> 1.5.38 (4 CVEs in logback-core) - jsoup 1.21.1 -> 1.23.2 (CVE-2026-71497) - assertj-core 3.27.3 -> 3.27.7 (CVE-2026-24400, test scope) - poi 5.4.1 -> 5.5.1 - slf4j 2.0.17 -> 2.0.19 Transitive dependencies pinned in a new dependencyManagement section: - bouncycastle *-jdk18on -> 1.86 (2 critical, 1 high, 2 moderate) - junrar -> 7.6.1 (3 path traversal CVEs) - log4j-api -> 2.26.1 (CVE-2026-49844) - commons-lang3 -> 3.20.0 (CVE-2025-48924) - commons-compress -> 1.28.0 - commons-io -> 2.20.0 - jackson-bom imported so tika's transitive jackson follows too sedalib excludes bcprov-jdk15on, an end-of-life branch frozen at 1.68 with five unpatched CVEs, and replaces it with bcprov-jdk18on, which exposes the same packages to truevfs-comp-zip. commons-io is pinned because droid-core-interfaces forces 2.15.1, which lacks FileTimes.fromUnixTime(long) required by commons-compress 1.28.0. Tika stays on 3.2.3: 3.3.2 changes PPTX extraction (slide order scrambled, slide-master placeholders emitted) and breaks TestTextExtraction. Its vulnerable transitive dependencies are covered by the pins above anyway. Two findings remain, both from droid 6.8.0 and without any upstream fix on those branches: commons-lang 2.6 (CVE-2025-48924) and commons-configuration 1.10 (CVE-2025-46392). Droid 6.9.x moves to commons-lang3 and commons-configuration2 and would clear both, but it is a wider change.
|
Fixed Issues (69)Great job! The following issues were fixed in this Pull Request
Use @Checkmarx to take action directly from this PR:
Try it: |
Regzox
force-pushed
the
story_16914
branch
3 times, most recently
from
September 22, 2026 15:31
47d7387 to
ac937f8
Compare
mkhediri
approved these changes
Sep 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.





No description provided.