Skip to content

Build the 14.14 SBOM with java 17 and take the BSD half of node-forge - #9425

Merged
manolo merged 1 commit into
14.14from
sbom-14.14-fixes
Sep 13, 2026
Merged

manolo merged 1 commit into
14.14from
sbom-14.14-fixes

Conversation

@manolo

@manolo manolo commented Sep 13, 2026

Copy link
Copy Markdown
Member

Summary

  • Build with java 17: the vaadin-maven-plugin in 14.14.0 cannot read class file major version 65, so build-frontend fails on java 21
  • Take the BSD-3-Clause half of the node-forge dual license, since the license summary splits OR expressions and checks each half on its own

Context

Six of the seven 14.14 GA releases already have their SBOM. 14.14.0 is the one that fails, and it fails on every attempt with Unsupported class file major version 65. With java 17 it builds. The node-forge entry showed up as Invalid license 'GPL-2.0' in every report.

The plugin in 14.14.0 cannot read class file major version 65, and the
license summary splits OR expressions, so the GPL half of node-forge was
reported as invalid.
@github-actions

Copy link
Copy Markdown
Contributor

Dependencies Report

  • 🚫 Vulnerabilities:

    • Vulnerabilities in: pkg:maven/com.vaadin/vaadin@14.14-SNAPSHOT [CVE-2026-2742] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/com.vaadin/flow-server@2.13-SNAPSHOT [CVE-2026-2742] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/commons-fileupload/commons-fileupload@1.5 [CVE-2025-48976] (osv-bomber,osv-scan,owasp)
      · cpe:2.3:a:apache:commons_fileupload::::::::
      · cpe:2.3:a:apache:commons_fileupload:2.0.0:m1::::::
      · cpe:2.3:a:apache:commons_fileupload:2.0.0:m1-rc1::::::
      · cpe:2.3:a:apache:commons_fileupload:2.0.0:m2::::::
      · cpe:2.3:a:apache:commons_fileupload:2.0.0:m2-rc1::::::
      · cpe:2.3:a:apache:commons_fileupload:2.0.0:m3::::::
      · cpe:2.3:a:apache:commons_fileupload:2.0.0:m3-rc1::::::
    • Vulnerabilities in: pkg:maven/org.jsoup/jsoup@1.15.3 [CVE-2026-71497] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/org.apache.commons/commons-lang3@3.14.0 [CVE-2025-48924] (osv-bomber,osv-scan,owasp)
      · cpe:2.3:a:apache:commons_lang::::::::
    • Vulnerabilities in: pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.4.2 [CVE-2026-50193, CVE-2026-54515, CVE-2026-54514, CVE-2026-54512, CVE-2026-54513, CVE-2023-35116] (osv-bomber,osv-scan,owasp)
      · cpe:2.3:a:fasterxml:jackson-databind::::::::
      · cpe:2.3:a:fasterxml:jackson-databind:2.22.0:::::::*
    • Vulnerabilities in: pkg:maven/com.fasterxml.jackson.core/jackson-core@2.13.4 [CVE-2025-52999, GHSA-r7wm-3cxj-wff9] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/org.springframework/spring-webmvc@5.3.31 [CVE-2026-41845, CVE-2026-22737, CVE-2026-22735, CVE-2026-22745, CVE-2026-41843, CVE-2026-41846, CVE-2026-41853, CVE-2024-38816, CVE-2024-38819, CVE-2026-41844, CVE-2026-41841, CVE-2025-41242, CVE-2024-38828, CVE-2026-22741, CVE-2026-41842] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/org.springframework/spring-context@5.3.31 [CVE-2024-38820, CVE-2025-22233] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/org.springframework/spring-core@5.3.31 [CVE-2026-41848, CVE-2025-41249, CVE-2026-41855, CVE-2026-47884, CVE-2026-47891, CVE-2026-47892, CVE-2026-59313, CVE-2026-59283, CVE-2024-22259, CVE-2026-41838, CVE-2026-41842, CVE-2026-41849, CVE-2026-41850, CVE-2026-41851, CVE-2026-47886, CVE-2026-47888, CVE-2026-47893, CVE-2026-59282, CVE-2026-22740, CVE-2026-41844, CVE-2026-41845, CVE-2026-41846, CVE-2026-47887, CVE-2026-59281, CVE-2026-22737, CVE-2026-41840, CVE-2026-41841, CVE-2026-41843, CVE-2024-38820, CVE-2026-22745, CVE-2026-41847, CVE-2026-41852, CVE-2026-41853, CVE-2024-38808, CVE-2026-59280, CVE-2026-41839, CVE-2026-59314, CVE-2026-22741, CVE-2026-22735] (osv-bomber,osv-scan,owasp)
      · cpe:2.3:a:vmware:spring_framework::::::::
      ·
      · cpe:2.3:a:netapp:active_iq_unified_manager:-:::::linux::
      · cpe:2.3:a:netapp:active_iq_unified_manager:-:::::vmware_vsphere::
      · cpe:2.3:a:netapp:active_iq_unified_manager:-:::::windows::
      · cpe:2.3:a:netapp:oncommand_insight:-:::::::*
    • Vulnerabilities in: pkg:maven/org.springframework/spring-expression@5.3.31 [CVE-2026-41849, CVE-2024-38808, CVE-2026-41852, CVE-2026-41850, CVE-2026-41851] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/org.springframework/spring-websocket@5.3.31 [CVE-2025-41254, CVE-2026-41838] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/org.springframework.boot/spring-boot@2.7.18 [CVE-2025-22235, CVE-2026-40973, CVE-2026-40974, CVE-2026-22733, CVE-2026-40972, CVE-2026-40975, CVE-2026-40977, CVE-2026-41001] (osv-bomber,osv-scan,owasp)
      ·
      · cpe:2.3:a:vmware:spring_boot::::::::
    • Vulnerabilities in: pkg:maven/org.springframework.boot/spring-boot-autoconfigure@2.7.18 [CVE-2026-41001] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/ch.qos.logback/logback-classic@1.2.12 [CVE-2023-6378] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/ch.qos.logback/logback-core@1.2.12 [CVE-2025-11226, CVE-2024-12801, CVE-2023-6481, CVE-2026-10532, CVE-2026-9828, CVE-2024-12798, CVE-2026-1225, CVE-2023-6378] (osv-bomber,osv-scan,owasp)
      ·
      · cpe:2.3:a:qos:logback:1.2.12:::::::*
      · cpe:2.3:a:qos:logback:1.3.13:::::::*
      · cpe:2.3:a:qos:logback:1.4.13:::::::*
      · cpe:2.3:a:qos:logback::::::::
    • Vulnerabilities in: pkg:maven/org.apache.logging.log4j/log4j-api@2.17.2 [CVE-2026-49844, CVE-2026-34479, CVE-2026-34477] (osv-bomber,osv-scan,owasp)
      · cpe:2.3:a:apache:log4j::::::::
      · cpe:2.3:a:apache:log4j:2.26.0:::::::*
      · cpe:2.3:a:apache:log4j:3.0.0:alpha1::::::
      · cpe:2.3:a:apache:log4j:3.0.0:alpha1_rc1::::::
      · cpe:2.3:a:apache:log4j:3.0.0:alpha1_rc2::::::
      · cpe:2.3:a:apache:log4j:3.0.0:beta1::::::
      · cpe:2.3:a:apache:log4j:3.0.0:beta2::::::
      · cpe:2.3:a:apache:log4j:3.0.0:beta3::::::
    • Vulnerabilities in: pkg:maven/org.yaml/snakeyaml@1.30 [CVE-2022-25857, CVE-2022-38751, CVE-2022-38752, CVE-2022-38749, CVE-2022-38750, CVE-2022-1471, CVE-2022-41854] (osv-bomber,osv-scan,owasp)
      · cpe:2.3:a:snakeyaml_project:snakeyaml::::::::
    • Vulnerabilities in: pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.83 [CVE-2025-55668, CVE-2025-53506, CVE-2024-56337, CVE-2025-31650, CVE-2025-49124, CVE-2025-52434, CVE-2026-24880, CVE-2024-50379, CVE-2026-43515, CVE-2026-43513, CVE-2024-38286, CVE-2024-24549, CVE-2025-24813, CVE-2026-25854, CVE-2026-43514, CVE-2026-65905, CVE-2025-31651, CVE-2025-66614, CVE-2026-42498, CVE-2026-65182, CVE-2025-48989, CVE-2026-41284, CVE-2025-46701, CVE-2025-48988, CVE-2026-68525, CVE-2026-43512, CVE-2025-61795, CVE-2026-24734, CVE-2026-41293, CVE-2026-34483, CVE-2025-55754, CVE-2025-49125, CVE-2024-34750, CVE-2025-55752, CVE-2025-52520, CVE-2026-34487, BIT-tomcat-2025-55668, BIT-tomcat-2025-53506, BIT-tomcat-2024-56337, BIT-tomcat-2025-31650, BIT-tomcat-2025-49124, BIT-tomcat-2025-52434, BIT-tomcat-2026-24880, BIT-tomcat-2024-50379, BIT-tomcat-2026-43515, BIT-tomcat-2026-43513, BIT-tomcat-2024-38286, BIT-tomcat-2024-24549, BIT-tomcat-2025-24813, BIT-tomcat-2026-25854, BIT-tomcat-2026-43514, BIT-tomcat-2026-65905, BIT-tomcat-2025-31651, BIT-tomcat-2025-66614, BIT-tomcat-2026-42498, BIT-tomcat-2026-65182, BIT-tomcat-2025-48989, BIT-tomcat-2026-41284, BIT-tomcat-2025-46701, BIT-tomcat-2025-48988, BIT-tomcat-2026-68525, BIT-tomcat-2026-43512, BIT-tomcat-2025-61795, BIT-tomcat-2026-24734, BIT-tomcat-2026-41293, BIT-tomcat-2026-34483, BIT-tomcat-2025-55754, BIT-tomcat-2025-49125, BIT-tomcat-2024-34750, BIT-tomcat-2025-55752, BIT-tomcat-2025-52520, BIT-tomcat-2026-34487, CVE-2024-52316, CVE-2026-29145, CVE-2026-53434, CVE-2026-55276, CVE-2026-59083, CVE-2026-59084, CVE-2026-65183, CVE-2026-66422, CVE-2026-68569, CVE-2026-29146, CVE-2026-65927, CVE-2026-68763, CVE-2026-53404, CVE-2026-55957, CVE-2026-73180, CVE-2026-55955, CVE-2026-55956, CVE-2024-23672, CVE-2026-50229, CVE-2024-54677, CVE-2026-24733] (osv-bomber,osv-scan,owasp)
      · cpe:2.3:a:apache:tomcat::::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone1::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone10::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone11::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone12::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone13::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone14::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone15::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone16::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone17::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone18::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone19::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone2::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone20::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone21::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone22::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone23::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone24::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone25::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone26::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone27::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone3::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone4::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone5::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone6::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone7::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone8::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:milestone9::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone10::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone11::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone12::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone13::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone14::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone15::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone16::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone17::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone18::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone19::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone2::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone20::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone21::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone22::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone23::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone24::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone25::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone3::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone4::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone5::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone6::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone7::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone8::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone9::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone1::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone10::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone11::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone12::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone13::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone14::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone15::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone16::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone17::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone18::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone19::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone2::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone20::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone3::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone4::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone5::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone6::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone7::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone8::::::
      · cpe:2.3:a:apache:tomcat:10.1.0:milestone9::::::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone1::::::
      · cpe:2.3:a:netapp:ontap_tools:9:::::vmware_vsphere::
      · cpe:2.3:a:netapp:ontap_tools:10:::::vmware_vsphere::
      · cpe:2.3:a:apache:tomcat:11.0.0:milestone26::::::
      · cpe:2.3:a:apache:tomcat_native::::::::
      · cpe:2.3:a:apache:tomcat:9.0.0:-::::::
      ·
      · cpe:2.3:a:apache:tomcat:10.1.0:-::::::
      · cpe:2.3:a:apache:tomcat:10.0.0:milestone1::::::
      · cpe:2.3:a:apache:tomcat:10.0.0:milestone10::::::
      · cpe:2.3:a:apache:tomcat:10.0.0:milestone2::::::
      · cpe:2.3:a:apache:tomcat:10.0.0:milestone3::::::
      · cpe:2.3:a:apache:tomcat:10.0.0:milestone4::::::
      · cpe:2.3:a:apache:tomcat:10.0.0:milestone5::::::
      · cpe:2.3:a:apache:tomcat:10.0.0:milestone6::::::
      · cpe:2.3:a:apache:tomcat:10.0.0:milestone7::::::
      · cpe:2.3:a:apache:tomcat:10.0.0:milestone8::::::
      · cpe:2.3:a:apache:tomcat:10.0.0:milestone9::::::
    • Vulnerabilities in: pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.83 [CVE-2024-23672, BIT-tomcat-2024-23672] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/org.springframework/spring-web@5.3.31 [CVE-2024-38809, CVE-2024-22262, CVE-2024-38820, CVE-2016-1000027, CVE-2024-22243, CVE-2024-22259, CVE-2026-41855, CVE-2026-47884, CVE-2026-47891, CVE-2026-47892, CVE-2026-59313, CVE-2026-59283, CVE-2026-41838, CVE-2026-41842, CVE-2026-41848, CVE-2026-41849, CVE-2026-41850, CVE-2026-41851, CVE-2026-47886, CVE-2026-47888, CVE-2026-47893, CVE-2026-59282, CVE-2026-22740, CVE-2026-41844, CVE-2026-41845, CVE-2026-41846, CVE-2026-47887, CVE-2026-59281, CVE-2026-22737, CVE-2026-41840, CVE-2026-41841, CVE-2026-41843, CVE-2026-22745, CVE-2026-41847, CVE-2026-41852, CVE-2026-41853, CVE-2024-38808, CVE-2026-59280, CVE-2026-41839, CVE-2026-59314, CVE-2026-22741, CVE-2026-22735] (osv-bomber,osv-scan,owasp)
      ·
      · cpe:2.3:a:vmware:spring_framework::::::::
      · cpe:2.3:a:netapp:active_iq_unified_manager:-:::::linux::
      · cpe:2.3:a:netapp:active_iq_unified_manager:-:::::vmware_vsphere::
      · cpe:2.3:a:netapp:active_iq_unified_manager:-:::::windows::
      · cpe:2.3:a:netapp:oncommand_insight:-:::::::*
    • Vulnerabilities in: pkg:npm/webpack-dev-server@5.2.1 [CVE-2026-6402, CVE-2026-14620, CVE-2026-14631, CVE-2026-9595] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:npm/webpack@5.99.6 [CVE-2025-68157, CVE-2025-68458] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:npm/dompurify@2.5.7 [CVE-2026-65903, CVE-2026-75838, CVE-2026-65902, CVE-2026-66010, CVE-2026-65913, CVE-2026-65912, CVE-2026-65898, CVE-2026-41239, CVE-2026-41240, CVE-2026-65914, CVE-2026-49458, CVE-2026-49459, CVE-2026-49978, CVE-2026-0540, CVE-2025-15599, CVE-2025-26791, CVE-2026-65899, CVE-2026-65901] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:npm/highcharts@6.1.4 [CVE-2021-29489, GHSA-gr4j-r575-g665] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:npm/serialize-javascript@6.0.2 [GHSA-5c6j-r48x-rmvq, CVE-2026-34043] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:npm/qs@6.15.3 [CVE-2026-82417, CVE-2026-82562] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:npm/uuid@8.3.2 [CVE-2026-41907, CVE-2026-41988] (osv-bomber,osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/tools.jackson.core/jackson-core@2.13.4 [] ()
      ·
    • Vulnerabilities in: pkg:maven/tools.jackson.core/jackson-databind@2.13.4.2 [CVE-2026-54515, CVE-2026-54514, CVE-2026-54512, CVE-2026-54513] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/com.vaadin/vaadin@2.13-SNAPSHOT [CVE-2026-2742] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/com.vaadin/flow-server@14.14-SNAPSHOT [CVE-2026-2742] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/org.apache.commons/commons-fileupload2-core@1.5 [CVE-2025-48976] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/commons-lang/commons-lang@3.14.0 [CVE-2025-48924] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.83 [BIT-tomcat-2025-55668, CVE-2025-55668, BIT-tomcat-2024-56337, CVE-2024-56337, BIT-tomcat-2025-49124, CVE-2025-49124, BIT-tomcat-2024-50379, CVE-2024-50379, BIT-tomcat-2026-43515, CVE-2026-43515, BIT-tomcat-2026-43513, CVE-2026-43513, BIT-tomcat-2025-24813, CVE-2025-24813, BIT-tomcat-2026-25854, CVE-2026-25854, BIT-tomcat-2026-43514, CVE-2026-43514, BIT-tomcat-2026-65905, CVE-2026-65905, BIT-tomcat-2025-31651, CVE-2025-31651, BIT-tomcat-2026-42498, CVE-2026-42498, BIT-tomcat-2026-65182, CVE-2026-65182, BIT-tomcat-2026-41284, CVE-2026-41284, BIT-tomcat-2025-46701, CVE-2025-46701, BIT-tomcat-2025-48988, CVE-2025-48988, BIT-tomcat-2026-68525, CVE-2026-68525, BIT-tomcat-2026-43512, CVE-2026-43512, BIT-tomcat-2025-61795, CVE-2025-61795, BIT-tomcat-2026-34483, CVE-2026-34483, BIT-tomcat-2025-55754, CVE-2025-55754, BIT-tomcat-2025-49125, CVE-2025-49125, BIT-tomcat-2025-55752, CVE-2025-55752, BIT-tomcat-2025-52520, CVE-2025-52520] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.83 [BIT-tomcat-2025-53506, CVE-2025-53506, BIT-tomcat-2025-31650, CVE-2025-31650, BIT-tomcat-2025-52434, CVE-2025-52434, BIT-tomcat-2026-24880, CVE-2026-24880, BIT-tomcat-2024-38286, CVE-2024-38286, BIT-tomcat-2024-24549, CVE-2024-24549, BIT-tomcat-2025-66614, CVE-2025-66614, BIT-tomcat-2025-48989, CVE-2025-48989, BIT-tomcat-2026-24734, CVE-2026-24734, BIT-tomcat-2026-41293, CVE-2026-41293, BIT-tomcat-2024-34750, CVE-2024-34750] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/org.apache.tomcat/tomcat-embed-core@9.0.83 [BIT-tomcat-2024-56337, CVE-2024-56337] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/org.apache.tomcat/tomcat@9.0.83 [BIT-tomcat-2025-49124, CVE-2025-49124, BIT-tomcat-2026-43515, CVE-2026-43515, BIT-tomcat-2026-43513, CVE-2026-43513, BIT-tomcat-2026-25854, CVE-2026-25854, BIT-tomcat-2026-43514, CVE-2026-43514, BIT-tomcat-2026-65905, CVE-2026-65905, BIT-tomcat-2025-66614, CVE-2025-66614, BIT-tomcat-2026-42498, CVE-2026-42498, BIT-tomcat-2026-65182, CVE-2026-65182, BIT-tomcat-2026-41284, CVE-2026-41284, BIT-tomcat-2026-68525, CVE-2026-68525, BIT-tomcat-2026-43512, CVE-2026-43512, BIT-tomcat-2025-61795, CVE-2025-61795, BIT-tomcat-2026-41293, CVE-2026-41293, BIT-tomcat-2026-34483, CVE-2026-34483, BIT-tomcat-2025-55754, CVE-2025-55754, BIT-tomcat-2025-55752, CVE-2025-55752, BIT-tomcat-2026-34487, CVE-2026-34487] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.83 [BIT-tomcat-2026-34487, CVE-2026-34487] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/org.apache.tomcat/tomcat-websocket@9.0.83 [BIT-tomcat-2024-23672, CVE-2024-23672] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/org.springframework/spring-webflux@5.3.31 [CVE-2026-22737, CVE-2026-22735, CVE-2026-22745, CVE-2026-41843, CVE-2026-41853, CVE-2024-38816, CVE-2024-38819, CVE-2026-41844, CVE-2026-41841, CVE-2026-22741, CVE-2026-41842] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/be.cylab/snakeyaml@1.30 [CVE-2022-38749] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/com.alipay.sofa.acts/acts-common-util@1.30 [CVE-2022-38749] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/io.prometheus.jmx/jmx_prometheus_httpserver@1.30 [CVE-2022-38749] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/io.prometheus.jmx/jmx_prometheus_httpserver_java6@1.30 [CVE-2022-38749] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/org.testifyproject.external/external-snakeyaml@1.30 [CVE-2022-38749] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/pl.droidsonroids.yaml/snakeyaml@1.30 [CVE-2022-38749] (osv-scan)
      ·
    • Vulnerabilities in: pkg:maven/com.vaadin/vaadin-core@14.14-20260913.094054-334 [CVE-2026-2742, CVE-2026-2741] (owasp)
      · cpe:2.3:a:vaadin:vaadin::::::::
    • Vulnerabilities in: pkg:maven/com.vaadin/vaadin-core@14.14-SNAPSHOT [CVE-2026-2742, CVE-2026-2741] (owasp)
      · cpe:2.3:a:vaadin:vaadin::::::::
  • 🟠 Changes in 14.14-SNAPSHOT since V14.14.6

    • 2 packages removed (0 external, 2 vaadin)
    • 10 packages modified (0 external, 10 vaadin)
    • 680 packages same (586 external, 94 vaadin)

[Click for more Details]

@manolo
manolo merged commit d023962 into 14.14 Sep 13, 2026
2 of 4 checks passed
@manolo
manolo deleted the sbom-14.14-fixes branch September 13, 2026 10:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant