Skip to content

Fix Security Violation#126

Open
agrasth wants to merge 1 commit intomasterfrom
violationFix
Open

Fix Security Violation#126
agrasth wants to merge 1 commit intomasterfrom
violationFix

Conversation

@agrasth
Copy link
Copy Markdown
Contributor

@agrasth agrasth commented Mar 13, 2026

  • All tests passed. If this feature is not already covered by the tests, I added new tests.

Title: Fix security audit violations - upgrade jackson, netty, plexus-archiver, build-info

Description:
Upgrade vulnerable direct dependencies to resolve jf audit security violations.

  • jackson (core/databind/annotations/dataformat-xml/datatype-guava): 2.18.2 → 2.18.6
  • netty (all modules): 4.1.125.Final → 4.1.130.Final
  • plexus-archiver: 4.10.0 → 4.10.3 (fixes CVE-2025-67721)
  • build-info-extractor: 2.43.4 → 2.43.6

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants