Skip to content

Update Mend: high confidence minor and patch dependency updates #3

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

mend-for-gb.xjqchip.workers.dev[bot]
Copy link

@mend-for-gb.xjqchip.workers.dev mend-for-gb.xjqchip.workers.dev bot commented Oct 28, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
net.sf.ehcache:ehcache (source) 2.10.4 -> 2.10.9.2 age adoption passing confidence
commons-io:commons-io (source) 2.5 -> 2.19.0 age adoption passing confidence
net.minidev:json-smart (source) 2.5.1 -> 2.5.2 age adoption passing confidence
com.nimbusds:nimbus-jose-jwt 9.37.3 -> 9.48 age adoption passing confidence
org.slf4j:slf4j-api (source, changelog) 1.7.25 -> 1.7.36 age adoption passing confidence
joda-time:joda-time (source) 2.10.10 -> 2.14.0 age adoption passing confidence
com.google.guava:guava 32.0.1-jre -> 32.1.3-jre age adoption passing confidence
com.google.code.gson:gson 2.11.0 -> 2.13.1 age adoption passing confidence
com.google.protobuf:protobuf-java (source) 4.27.0 -> 4.31.1 age adoption passing confidence
org.ow2.asm:asm (source) 9.3 -> 9.8 age adoption passing confidence
javax.xml.bind:jaxb-api 2.2.2 -> 2.3.1 age adoption passing confidence
net.minidev:json-smart (source) 2.5.0 -> 2.5.2 age adoption passing confidence
com.github.javaparser:javaparser-core (source) 3.18.0 -> 3.26.4 age adoption passing confidence
io.dropwizard.metrics:metrics-core (source) 4.1.4 -> 4.2.32 age adoption passing confidence
io.grpc:grpc-context 1.49.2 -> 1.73.0 age adoption passing confidence
commons-cli:commons-cli (source) 1.2 -> 1.9.0 age adoption passing confidence
org.xmlunit:xmlunit-core (source) 2.8.2 -> 2.10.2 age adoption passing confidence
com.github.tomakehurst:wiremock-jre8-standalone (source) 2.23.2 -> 2.35.2 age adoption passing confidence
io.projectreactor:reactor-core 3.4.38 -> 3.7.6 age adoption passing confidence
org.yaml:snakeyaml 2.0 -> 2.4 age adoption passing confidence
com.google.http-client:google-http-client-jackson2 1.42.3 -> 1.47.0 age adoption passing confidence
org.hdrhistogram:HdrHistogram (source) 2.1.9 -> 2.2.2 age adoption passing confidence
org.reflections:reflections 0.9.12 -> 0.10.2 age adoption passing confidence
org.apache.maven:maven-model 3.6.2 -> 3.9.9 age adoption passing confidence
org.apache.commons:commons-lang3 (source) 3.14.0 -> 3.17.0 age adoption passing confidence
org.apache.commons:commons-compress (source) 1.26.1 -> 1.27.1 age adoption passing confidence
com.google.auth:google-auth-library-oauth2-http 1.11.0 -> 1.36.0 age adoption passing confidence
org.apache.commons:commons-collections4 (source) 4.4 -> 4.5.0 age adoption passing confidence
com.unboundid:unboundid-ldapsdk 6.0.3 -> 6.0.11 age adoption passing confidence
joda-time:joda-time (source) 2.10.14 -> 2.14.0 age adoption passing confidence
org.apache.commons:commons-lang3 (source) 3.11 -> 3.17.0 age adoption passing confidence
commons-io:commons-io (source) 2.8.0 -> 2.19.0 age adoption passing confidence
com.sun.xml.bind:jaxb-impl (source) 2.2.3-1 -> 2.3.9 age adoption passing confidence
com.google.code.gson:gson 2.10 -> 2.13.1 age adoption passing confidence
net.java.dev.jna:jna 5.10.0 -> 5.17.0 age adoption passing confidence
javax.mail:mail (source) 1.4.5 -> 1.4.7 age adoption passing confidence
com.microsoft.azure:msal4j 1.16.2 -> 1.20.1 age adoption passing confidence
commons-io:commons-io (source) 2.15.1 -> 2.19.0 age adoption passing confidence
io.grpc:grpc-context 1.27.2 -> 1.73.0 age adoption passing confidence
org.slf4j:slf4j-nop (source, changelog) 2.0.10 -> 2.0.17 age adoption passing confidence
org.slf4j:jcl-over-slf4j (source, changelog) 2.0.10 -> 2.0.17 age adoption passing confidence
commons-codec:commons-codec (source) 1.16.1 -> 1.18.0 age adoption passing confidence
com.sun.activation:jakarta.activation 1.2.1 -> 1.2.2 age adoption passing confidence
org.apache.poi:poi-ooxml 5.2.5 -> 5.4.1 age adoption passing confidence
org.apache.pdfbox:pdfbox (source) 2.0.31 -> 2.0.34 age adoption passing confidence
com.azure:azure-storage-blob 12.27.1 -> 12.30.0 age adoption passing confidence
org.apache.tika:tika-parser-text-module (source) 2.9.2 -> 2.9.4 age adoption passing confidence
org.skyscreamer:jsonassert 1.5.0 -> 1.5.3 age adoption passing confidence
com.azure:azure-identity 1.13.2 -> 1.16.1 age adoption passing confidence
com.maxmind.geoip2:geoip2 (source) 4.2.0 -> 4.3.1 age adoption passing confidence
com.azure:azure-core 1.51.0 -> 1.55.3 age adoption passing confidence
org.ow2.asm:asm (source) 9.7 -> 9.8 age adoption passing confidence
com.google.cloud:google-cloud-storage 2.13.1 -> 2.52.3 age adoption passing confidence
gradle.plugin.org.jetbrains.gradle.plugin.idea-ext:gradle-idea-ext 1.1.4 -> 1.1.10 age adoption passing confidence
com.github.spullara.mustache.java:compiler 0.9.10 -> 0.9.14 age adoption passing confidence
org.apache.httpcomponents:httpcore 4.4.12 -> 4.4.16 age adoption passing confidence
org.fusesource.jansi:jansi (source) 2.4.0 -> 2.4.2 age adoption passing confidence
org.checkerframework:checker-qual (source) 3.42.0 -> 3.49.3 age adoption passing confidence
commons-io:commons-io (source) 2.2 -> 2.19.0 age adoption passing confidence
com.fasterxml.jackson.core:jackson-core 2.17.2 -> 2.19.0 age adoption passing confidence
commons-codec:commons-codec (source) 1.11 -> 1.18.0 age adoption passing confidence
com.gradle.develocity 3.17.4 -> 3.19.2 age adoption passing confidence
net.bytebuddy:byte-buddy 1.14.12 -> 1.17.5 age adoption passing confidence
org.apache.ant:ant (source) 1.10.12 -> 1.10.15 age adoption passing confidence
com.fasterxml.jackson.core:jackson-databind (source) 2.15.0 -> 2.19.0 age adoption passing confidence
com.fasterxml.jackson.core:jackson-core 2.15.0 -> 2.19.0 age adoption passing confidence
org.ow2.asm:asm (source) 9.6 -> 9.8 age adoption passing confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

netplex/json-smart-v2 (net.minidev:json-smart)

v2.5.2

Compare Source

About CVE-2024-57699

Thanks for @​ccudennec-otto Some remarks on the CVE, more discussions in #​236

  • as mentioned here it is quite unlikely that the vulnerability is exploited if you come here because of Spring Security / com.nimbusds:oauth2-oidc-sdk
  • the code changes for the upcoming release will "only" fix the default modes provided by JSONParser, e.g. MODE_RFC4627
  • if you create the JSONParser manually / with custom options, make sure you set option LIMIT_JSON_DEPTH
    • since that's what "connect2id" is doing in their library, they were responsible for fixing it. They've already provided a new 11.x release that fixes the JSONParser setup on their side, i.e. you rather need their fixed version and not version 2.5.2 of json-smart
    • as stated here, they would also need to backport the fix to the versions that Spring Security needs IMHO
What's Changed

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

@mend-for-gb.xjqchip.workers.dev mend-for-gb.xjqchip.workers.dev bot force-pushed the whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates branch 5 times, most recently from c0ee338 to c5ff0ae Compare November 2, 2024 17:29
@mend-for-gb.xjqchip.workers.dev mend-for-gb.xjqchip.workers.dev bot force-pushed the whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates branch 2 times, most recently from 8280754 to 3b0c65f Compare November 9, 2024 16:32
@mend-for-gb.xjqchip.workers.dev mend-for-gb.xjqchip.workers.dev bot force-pushed the whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates branch 5 times, most recently from 6cc79e4 to bff8174 Compare November 20, 2024 03:42
@mend-for-gb.xjqchip.workers.dev mend-for-gb.xjqchip.workers.dev bot force-pushed the whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates branch 5 times, most recently from c49ec10 to 0f546fb Compare November 28, 2024 13:07
@mend-for-gb.xjqchip.workers.dev mend-for-gb.xjqchip.workers.dev bot force-pushed the whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates branch 6 times, most recently from cfc9e7e to e8a1910 Compare December 7, 2024 11:21
@mend-for-gb.xjqchip.workers.dev mend-for-gb.xjqchip.workers.dev bot force-pushed the whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates branch 5 times, most recently from 3e89249 to 8ea6472 Compare December 14, 2024 12:19
@mend-for-gb.xjqchip.workers.dev mend-for-gb.xjqchip.workers.dev bot force-pushed the whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates branch 2 times, most recently from 6c917b3 to 3d552ee Compare December 17, 2024 18:07
@mend-for-gb.xjqchip.workers.dev mend-for-gb.xjqchip.workers.dev bot force-pushed the whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates branch 6 times, most recently from 043e52e to f71f44c Compare May 7, 2025 12:58
@mend-for-gb.xjqchip.workers.dev mend-for-gb.xjqchip.workers.dev bot force-pushed the whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates branch 7 times, most recently from 5cb676e to 6b4d183 Compare May 15, 2025 22:01
@mend-for-gb.xjqchip.workers.dev mend-for-gb.xjqchip.workers.dev bot force-pushed the whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates branch 7 times, most recently from bcde7ad to 16be3d5 Compare May 23, 2025 14:33
@mend-for-gb.xjqchip.workers.dev mend-for-gb.xjqchip.workers.dev bot force-pushed the whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates branch 6 times, most recently from 22f56e9 to e93f2e8 Compare May 30, 2025 15:33
@mend-for-gb.xjqchip.workers.dev mend-for-gb.xjqchip.workers.dev bot force-pushed the whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates branch 2 times, most recently from 2303e6b to 685cca6 Compare June 1, 2025 16:10
@mend-for-gb.xjqchip.workers.dev mend-for-gb.xjqchip.workers.dev bot force-pushed the whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates branch from 685cca6 to 0005569 Compare June 2, 2025 17:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants