Skip to content

[cuebot] Pin commons-collections to 3.2.2 - #2582

Open
jamescamping wants to merge 1 commit into
AcademySoftwareFoundation:masterfrom
jamescamping:fix/cuebot-commons-collections-3.2.2
Open

jamescamping wants to merge 1 commit into
AcademySoftwareFoundation:masterfrom
jamescamping:fix/cuebot-commons-collections-3.2.2

Conversation

@jamescamping

@jamescamping jamescamping commented Oct 5, 2026 •

Copy link
Copy Markdown

Related Issues

Fixes #2581

Summarize your change.

velocity:1.7 transitively pulls in commons-collections:3.2.1, which is affected by CVE-2015-7501 and CVE-2015-6420 (unsafe deserialization via InvokerTransformer). Dependency scanners flag cuebot for both.

This adds an explicit commons-collections:3.2.2 dependency, which is the upstream fix and a drop-in replacement for 3.2.1. Cuebot has no direct commons-collections imports; the only consumer is Velocity via EmailSupport.

Testing:

  • ./gradlew dependencies --configuration runtimeClasspath now resolves commons-collections:3.2.1 -> 3.2.2
  • ./gradlew compileJava passes with -Werror
  • ./gradlew test: 1102 tests, 0 failures, 0 errors

LLM usage disclosure

Assisted-by: Claude Code / Claude Sonnet 5.5

Claude Code was used to trace the flagged CVEs to the transitive dependency path (gradlew dependencies), propose the pin, and run the build and test suite. I reviewed the change and verified the results myself.

Summary by CodeRabbit

  • Chores
    • Updated a supporting library used by the application. No user-facing changes are included in this update.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 4aecc79c-1181-4215-bf0f-f3b90e8a5b1f
📥 Commits

Reviewing files that changed from the base of the PR and between 08379d8 and f315776.

📒 Files selected for processing (1)
  • cuebot/build.gradle

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 3 remain after this review.


📝 Walkthrough

Walkthrough

Cuebot now declares Apache Commons Collections version 3.2.2 as an implementation dependency.

Changes

Cuebot dependency update

Layer / File(s) Summary
Commons Collections dependency declaration
cuebot/build.gradle
Adds commons-collections:commons-collections version 3.2.2 as an implementation dependency.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~5 minutes

Change: Other · Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to f3157

The dependency is expected to resolve to 3.2.2 at runtime, with no conflicting managed version found. No concrete merge-blocking risk is evident; the exact runtime resolution was not executed.

Architecture Summary

Architecture risk: 🔵 Low · up to f3157

The change affects 1 system.

Changed systems: cuebot

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — cuebot (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in cuebot/build.gradle: Adds commons-collections:commons-collections version 3.2.2 as an implementation dependency.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the change: pinning cuebot’s commons-collections dependency to version 3.2.2.
Linked Issues check ✅ Passed Issue #2581 requires the runtime classpath to resolve commons-collections to 3.2.2 or later. cuebot/build.gradle adds commons-collections:3.2.2 as an implementation dependency, overriding Velocity 1.7…
Out of Scope Changes check ✅ Passed The reported change adds only the commons-collections dependency pin in cuebot/build.gradle. This change directly addresses issue #2581. No unrelated change is indicated.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@linux-foundation-easycla

linux-foundation-easycla Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

CLA Signed
The committers listed above are authorized under a signed CLA.

  • ✅ login: jamescamping / name: James Camping (248d965)

velocity 1.7 transitively brings in commons-collections 3.2.1, which is
affected by CVE-2015-7501 and CVE-2015-6420 (unsafe deserialization in
InvokerTransformer). 3.2.2 is the upstream fix and is a drop-in
replacement. Cuebot does not import commons-collections directly; the
only consumer is Velocity via EmailSupport.

Assisted-by: Claude Code / Claude Sonnet 5.5
Signed-off-by: James Camping <camping@gmail.com>
@jamescamping
jamescamping force-pushed the fix/cuebot-commons-collections-3.2.2 branch from 248d965 to f315776 Compare October 5, 2026 18:02
@jamescamping
jamescamping marked this pull request as ready for review October 5, 2026 18:03

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[cuebot] commons-collections 3.2.1 (CVE-2015-7501, CVE-2015-6420) pulled in via velocity 1.7

1 participant