Repository navigation
build(deps): bump the maven group across 3 directories with 20 updates - #17
Closed
dependabot[bot] wants to merge 1 commit into
Closed
dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the maven group with 12 updates in the / directory: | Package | From | To | | --- | --- | --- | | [org.springframework:spring-core](https://github.com/spring-projects/spring-framework) | `5.3.39` | `6.2.19` | | [org.hibernate:hibernate-core](https://github.com/hibernate/hibernate-orm) | `5.6.15.Final` | `6.0.0.Final` | | [org.apache.jackrabbit:jackrabbit-jcr-commons](https://github.com/apache/jackrabbit) | `2.20.17` | `2.22.2` | | [org.apache.tika:tika-core](https://github.com/apache/tika) | `2.9.4` | `3.2.2` | | [org.apache.activemq:activemq-broker](https://github.com/apache/activemq) | `5.16.8` | `5.19.7` | | org.apache.logging.log4j:log4j-core | `2.25.3` | `2.25.4` | | [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) | `2.21.1` | `2.21.4` | | [org.jsoup:jsoup](https://github.com/jhy/jsoup) | `1.22.1` | `1.23.1` | | org.apache.cxf:cxf-core | `3.5.11` | `4.1.7` | | [org.bouncycastle:bcpg-jdk18on](https://github.com/bcgit/bc-java) | `1.83` | `1.84` | | [org.springframework.security:spring-security-core](https://github.com/spring-projects/spring-security) | `5.8.16` | `6.0.0` | | org.apache.tomcat:tomcat-catalina | `9.0.117` | `9.0.118` | Bumps the maven group with 10 updates in the /projects/sitemanage directory: | Package | From | To | | --- | --- | --- | | [org.springframework:spring-core](https://github.com/spring-projects/spring-framework) | `5.3.39` | `6.2.19` | | [org.hibernate:hibernate-core](https://github.com/hibernate/hibernate-orm) | `5.6.15.Final` | `6.0.0.Final` | | [org.apache.jackrabbit:jackrabbit-jcr-commons](https://github.com/apache/jackrabbit) | `2.20.17` | `2.22.2` | | [org.apache.tika:tika-core](https://github.com/apache/tika) | `2.9.4` | `3.2.2` | | [org.apache.activemq:activemq-broker](https://github.com/apache/activemq) | `5.16.8` | `5.19.7` | | org.apache.logging.log4j:log4j-core | `2.25.3` | `2.25.4` | | [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) | `2.21.1` | `2.21.4` | | [org.jsoup:jsoup](https://github.com/jhy/jsoup) | `1.22.1` | `1.23.1` | | org.apache.cxf:cxf-core | `3.5.11` | `4.1.7` | | [org.bouncycastle:bcpg-jdk18on](https://github.com/bcgit/bc-java) | `1.83` | `1.84` | Bumps the maven group with 10 updates in the /system directory: | Package | From | To | | --- | --- | --- | | [org.springframework:spring-core](https://github.com/spring-projects/spring-framework) | `5.3.39` | `6.2.19` | | [org.hibernate:hibernate-core](https://github.com/hibernate/hibernate-orm) | `5.6.15.Final` | `6.0.0.Final` | | [org.apache.jackrabbit:jackrabbit-jcr-commons](https://github.com/apache/jackrabbit) | `2.20.17` | `2.22.2` | | [org.apache.tika:tika-core](https://github.com/apache/tika) | `2.9.4` | `3.2.2` | | [org.apache.activemq:activemq-broker](https://github.com/apache/activemq) | `5.16.8` | `5.19.7` | | org.apache.logging.log4j:log4j-core | `2.25.3` | `2.25.4` | | [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) | `2.21.1` | `2.21.4` | | [org.jsoup:jsoup](https://github.com/jhy/jsoup) | `1.22.1` | `1.23.1` | | org.apache.cxf:cxf-core | `3.5.11` | `4.1.7` | | [org.bouncycastle:bcpg-jdk18on](https://github.com/bcgit/bc-java) | `1.83` | `1.84` | Updates `org.springframework:spring-core` from 5.3.39 to 6.2.19 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v5.3.39...v6.2.19) Updates `org.springframework:spring-expression` from 5.3.39 to 6.2.19 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v5.3.39...v6.2.19) Updates `org.springframework:spring-webmvc` from 5.3.39 to 6.2.19 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v5.3.39...v6.2.19) Updates `org.hibernate:hibernate-core` from 5.6.15.Final to 6.0.0.Final - [Release notes](https://github.com/hibernate/hibernate-orm/releases) - [Changelog](https://github.com/hibernate/hibernate-orm/blob/6.0.0/changelog.txt) - [Commits](hibernate/hibernate-orm@5.6.15...6.0.0) Updates `org.apache.jackrabbit:jackrabbit-jcr-commons` from 2.20.17 to 2.22.2 - [Changelog](https://github.com/apache/jackrabbit/blob/jackrabbit-2.22.2/RELEASE-NOTES.txt) - [Commits](apache/jackrabbit@jackrabbit-2.20.17...jackrabbit-2.22.2) Updates `org.apache.tika:tika-core` from 2.9.4 to 3.2.2 - [Changelog](https://github.com/apache/tika/blob/main/CHANGES.txt) - [Commits](apache/tika@2.9.4...3.2.2) Updates `org.apache.activemq:activemq-broker` from 5.16.8 to 5.19.7 - [Release notes](https://github.com/apache/activemq/releases) - [Commits](apache/activemq@activemq-5.16.8...activemq-5.19.7) Updates `org.apache.activemq:activemq-client` from 5.16.8 to 5.19.7 - [Release notes](https://github.com/apache/activemq/releases) - [Commits](apache/activemq@activemq-5.16.8...activemq-5.19.7) Updates `org.apache.logging.log4j:log4j-core` from 2.25.3 to 2.25.4 Updates `org.apache.logging.log4j:log4j-1.2-api` from 2.25.3 to 2.25.4 Updates `com.fasterxml.jackson.core:jackson-core` from 2.21.1 to 2.21.4 - [Commits](FasterXML/jackson-core@jackson-core-2.21.1...jackson-core-2.21.4) Updates `com.fasterxml.jackson.core:jackson-databind` from 2.21.1 to 2.21.4 - [Commits](https://github.com/FasterXML/jackson/commits) Updates `org.jsoup:jsoup` from 1.22.1 to 1.23.1 - [Release notes](https://github.com/jhy/jsoup/releases) - [Changelog](https://github.com/jhy/jsoup/blob/master/CHANGES.md) - [Commits](jhy/jsoup@jsoup-1.22.1...jsoup-1.23.1) Updates `org.apache.cxf:cxf-core` from 3.5.11 to 4.1.7 Updates `org.bouncycastle:bcpg-jdk18on` from 1.83 to 1.84 - [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html) - [Commits](https://github.com/bcgit/bc-java/commits) Updates `org.bouncycastle:bcpkix-jdk18on` from 1.83 to 1.84 - [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html) - [Commits](https://github.com/bcgit/bc-java/commits) Updates `org.bouncycastle:bcprov-jdk18on` from 1.83 to 1.84 - [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html) - [Commits](https://github.com/bcgit/bc-java/commits) Updates `org.springframework.security:spring-security-core` from 5.8.16 to 6.0.0 - [Release notes](https://github.com/spring-projects/spring-security/releases) - [Changelog](https://github.com/spring-projects/spring-security/blob/main/RELEASE.adoc) - [Commits](spring-projects/spring-security@5.8.16...6.0.0) Updates `org.springframework.security:spring-security-web` from 5.8.16 to 6.0.0 - [Release notes](https://github.com/spring-projects/spring-security/releases) - [Changelog](https://github.com/spring-projects/spring-security/blob/main/RELEASE.adoc) - [Commits](spring-projects/spring-security@5.8.16...6.0.0) Updates `org.apache.tomcat:tomcat-catalina` from 9.0.117 to 9.0.118 Updates `org.springframework:spring-core` from 5.3.39 to 6.2.19 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v5.3.39...v6.2.19) Updates `org.springframework:spring-expression` from 5.3.39 to 6.2.19 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v5.3.39...v6.2.19) Updates `org.springframework:spring-webmvc` from 5.3.39 to 6.2.19 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v5.3.39...v6.2.19) Updates `org.hibernate:hibernate-core` from 5.6.15.Final to 6.0.0.Final - [Release notes](https://github.com/hibernate/hibernate-orm/releases) - [Changelog](https://github.com/hibernate/hibernate-orm/blob/6.0.0/changelog.txt) - [Commits](hibernate/hibernate-orm@5.6.15...6.0.0) Updates `org.apache.jackrabbit:jackrabbit-jcr-commons` from 2.20.17 to 2.22.2 - [Changelog](https://github.com/apache/jackrabbit/blob/jackrabbit-2.22.2/RELEASE-NOTES.txt) - [Commits](apache/jackrabbit@jackrabbit-2.20.17...jackrabbit-2.22.2) Updates `org.apache.tika:tika-core` from 2.9.4 to 3.2.2 - [Changelog](https://github.com/apache/tika/blob/main/CHANGES.txt) - [Commits](apache/tika@2.9.4...3.2.2) Updates `org.apache.activemq:activemq-broker` from 5.16.8 to 5.19.7 - [Release notes](https://github.com/apache/activemq/releases) - [Commits](apache/activemq@activemq-5.16.8...activemq-5.19.7) Updates `org.apache.activemq:activemq-client` from 5.16.8 to 5.19.7 - [Release notes](https://github.com/apache/activemq/releases) - [Commits](apache/activemq@activemq-5.16.8...activemq-5.19.7) Updates `org.apache.logging.log4j:log4j-core` from 2.25.3 to 2.25.4 Updates `org.apache.logging.log4j:log4j-1.2-api` from 2.25.3 to 2.25.4 Updates `com.fasterxml.jackson.core:jackson-core` from 2.21.1 to 2.21.4 - [Commits](FasterXML/jackson-core@jackson-core-2.21.1...jackson-core-2.21.4) Updates `com.fasterxml.jackson.core:jackson-databind` from 2.21.1 to 2.21.4 - [Commits](https://github.com/FasterXML/jackson/commits) Updates `org.jsoup:jsoup` from 1.22.1 to 1.23.1 - [Release notes](https://github.com/jhy/jsoup/releases) - [Changelog](https://github.com/jhy/jsoup/blob/master/CHANGES.md) - [Commits](jhy/jsoup@jsoup-1.22.1...jsoup-1.23.1) Updates `org.apache.cxf:cxf-core` from 3.5.11 to 4.1.7 Updates `org.bouncycastle:bcpg-jdk18on` from 1.83 to 1.84 - [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html) - [Commits](https://github.com/bcgit/bc-java/commits) Updates `org.bouncycastle:bcpkix-jdk18on` from 1.83 to 1.84 - [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html) - [Commits](https://github.com/bcgit/bc-java/commits) Updates `org.bouncycastle:bcprov-jdk18on` from 1.83 to 1.84 - [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html) - [Commits](https://github.com/bcgit/bc-java/commits) Updates `org.springframework:spring-core` from 5.3.39 to 6.2.19 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v5.3.39...v6.2.19) Updates `org.springframework:spring-expression` from 5.3.39 to 6.2.19 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v5.3.39...v6.2.19) Updates `org.springframework:spring-webmvc` from 5.3.39 to 6.2.19 - [Release notes](https://github.com/spring-projects/spring-framework/releases) - [Commits](spring-projects/spring-framework@v5.3.39...v6.2.19) Updates `org.hibernate:hibernate-core` from 5.6.15.Final to 6.0.0.Final - [Release notes](https://github.com/hibernate/hibernate-orm/releases) - [Changelog](https://github.com/hibernate/hibernate-orm/blob/6.0.0/changelog.txt) - [Commits](hibernate/hibernate-orm@5.6.15...6.0.0) Updates `org.apache.jackrabbit:jackrabbit-jcr-commons` from 2.20.17 to 2.22.2 - [Changelog](https://github.com/apache/jackrabbit/blob/jackrabbit-2.22.2/RELEASE-NOTES.txt) - [Commits](apache/jackrabbit@jackrabbit-2.20.17...jackrabbit-2.22.2) Updates `org.apache.tika:tika-core` from 2.9.4 to 3.2.2 - [Changelog](https://github.com/apache/tika/blob/main/CHANGES.txt) - [Commits](apache/tika@2.9.4...3.2.2) Updates `org.apache.activemq:activemq-broker` from 5.16.8 to 5.19.7 - [Release notes](https://github.com/apache/activemq/releases) - [Commits](apache/activemq@activemq-5.16.8...activemq-5.19.7) Updates `org.apache.activemq:activemq-client` from 5.16.8 to 5.19.7 - [Release notes](https://github.com/apache/activemq/releases) - [Commits](apache/activemq@activemq-5.16.8...activemq-5.19.7) Updates `org.apache.logging.log4j:log4j-core` from 2.25.3 to 2.25.4 Updates `org.apache.logging.log4j:log4j-1.2-api` from 2.25.3 to 2.25.4 Updates `com.fasterxml.jackson.core:jackson-core` from 2.21.1 to 2.21.4 - [Commits](FasterXML/jackson-core@jackson-core-2.21.1...jackson-core-2.21.4) Updates `com.fasterxml.jackson.core:jackson-databind` from 2.21.1 to 2.21.4 - [Commits](https://github.com/FasterXML/jackson/commits) Updates `org.jsoup:jsoup` from 1.22.1 to 1.23.1 - [Release notes](https://github.com/jhy/jsoup/releases) - [Changelog](https://github.com/jhy/jsoup/blob/master/CHANGES.md) - [Commits](jhy/jsoup@jsoup-1.22.1...jsoup-1.23.1) Updates `org.apache.cxf:cxf-core` from 3.5.11 to 4.1.7 Updates `org.bouncycastle:bcpg-jdk18on` from 1.83 to 1.84 - [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html) - [Commits](https://github.com/bcgit/bc-java/commits) Updates `org.bouncycastle:bcpkix-jdk18on` from 1.83 to 1.84 - [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html) - [Commits](https://github.com/bcgit/bc-java/commits) Updates `org.bouncycastle:bcprov-jdk18on` from 1.83 to 1.84 - [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html) - [Commits](https://github.com/bcgit/bc-java/commits) --- updated-dependencies: - dependency-name: org.springframework:spring-core dependency-version: 6.2.19 dependency-type: direct:production dependency-group: maven - dependency-name: org.springframework:spring-expression dependency-version: 6.2.19 dependency-type: direct:production dependency-group: maven - dependency-name: org.springframework:spring-webmvc dependency-version: 6.2.19 dependency-type: direct:production dependency-group: maven - dependency-name: org.hibernate:hibernate-core dependency-version: 6.0.0.Final dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.jackrabbit:jackrabbit-jcr-commons dependency-version: 2.22.2 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.tika:tika-core dependency-version: 3.2.2 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.activemq:activemq-broker dependency-version: 5.19.7 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.activemq:activemq-client dependency-version: 5.19.7 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.logging.log4j:log4j-core dependency-version: 2.25.4 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.logging.log4j:log4j-1.2-api dependency-version: 2.25.4 dependency-type: direct:production dependency-group: maven - dependency-name: com.fasterxml.jackson.core:jackson-core dependency-version: 2.21.4 dependency-type: direct:production dependency-group: maven - dependency-name: com.fasterxml.jackson.core:jackson-databind dependency-version: 2.21.4 dependency-type: direct:production dependency-group: maven - dependency-name: org.jsoup:jsoup dependency-version: 1.23.1 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.cxf:cxf-core dependency-version: 4.1.7 dependency-type: direct:production dependency-group: maven - dependency-name: org.bouncycastle:bcpg-jdk18on dependency-version: '1.84' dependency-type: direct:production dependency-group: maven - dependency-name: org.bouncycastle:bcpkix-jdk18on dependency-version: '1.84' dependency-type: direct:production dependency-group: maven - dependency-name: org.bouncycastle:bcprov-jdk18on dependency-version: '1.84' dependency-type: direct:production dependency-group: maven - dependency-name: org.springframework.security:spring-security-core dependency-version: 6.0.0 dependency-type: direct:production dependency-group: maven - dependency-name: org.springframework.security:spring-security-web dependency-version: 6.0.0 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.tomcat:tomcat-catalina dependency-version: 9.0.118 dependency-type: direct:production dependency-group: maven - dependency-name: org.springframework:spring-core dependency-version: 6.2.19 dependency-type: direct:production dependency-group: maven - dependency-name: org.springframework:spring-expression dependency-version: 6.2.19 dependency-type: direct:production dependency-group: maven - dependency-name: org.springframework:spring-webmvc dependency-version: 6.2.19 dependency-type: direct:production dependency-group: maven - dependency-name: org.hibernate:hibernate-core dependency-version: 6.0.0.Final dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.jackrabbit:jackrabbit-jcr-commons dependency-version: 2.22.2 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.tika:tika-core dependency-version: 3.2.2 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.activemq:activemq-broker dependency-version: 5.19.7 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.activemq:activemq-client dependency-version: 5.19.7 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.logging.log4j:log4j-core dependency-version: 2.25.4 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.logging.log4j:log4j-1.2-api dependency-version: 2.25.4 dependency-type: direct:production dependency-group: maven - dependency-name: com.fasterxml.jackson.core:jackson-core dependency-version: 2.21.4 dependency-type: direct:production dependency-group: maven - dependency-name: com.fasterxml.jackson.core:jackson-databind dependency-version: 2.21.4 dependency-type: direct:production dependency-group: maven - dependency-name: org.jsoup:jsoup dependency-version: 1.23.1 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.cxf:cxf-core dependency-version: 4.1.7 dependency-type: direct:production dependency-group: maven - dependency-name: org.bouncycastle:bcpg-jdk18on dependency-version: '1.84' dependency-type: direct:production dependency-group: maven - dependency-name: org.bouncycastle:bcpkix-jdk18on dependency-version: '1.84' dependency-type: direct:production dependency-group: maven - dependency-name: org.bouncycastle:bcprov-jdk18on dependency-version: '1.84' dependency-type: direct:production dependency-group: maven - dependency-name: org.springframework:spring-core dependency-version: 6.2.19 dependency-type: direct:production dependency-group: maven - dependency-name: org.springframework:spring-expression dependency-version: 6.2.19 dependency-type: direct:production dependency-group: maven - dependency-name: org.springframework:spring-webmvc dependency-version: 6.2.19 dependency-type: direct:production dependency-group: maven - dependency-name: org.hibernate:hibernate-core dependency-version: 6.0.0.Final dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.jackrabbit:jackrabbit-jcr-commons dependency-version: 2.22.2 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.tika:tika-core dependency-version: 3.2.2 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.activemq:activemq-broker dependency-version: 5.19.7 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.activemq:activemq-client dependency-version: 5.19.7 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.logging.log4j:log4j-core dependency-version: 2.25.4 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.logging.log4j:log4j-1.2-api dependency-version: 2.25.4 dependency-type: direct:production dependency-group: maven - dependency-name: com.fasterxml.jackson.core:jackson-core dependency-version: 2.21.4 dependency-type: direct:production dependency-group: maven - dependency-name: com.fasterxml.jackson.core:jackson-databind dependency-version: 2.21.4 dependency-type: direct:production dependency-group: maven - dependency-name: org.jsoup:jsoup dependency-version: 1.23.1 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.cxf:cxf-core dependency-version: 4.1.7 dependency-type: direct:production dependency-group: maven - dependency-name: org.bouncycastle:bcpg-jdk18on dependency-version: '1.84' dependency-type: direct:production dependency-group: maven - dependency-name: org.bouncycastle:bcpkix-jdk18on dependency-version: '1.84' dependency-type: direct:production dependency-group: maven - dependency-name: org.bouncycastle:bcprov-jdk18on dependency-version: '1.84' dependency-type: direct:production dependency-group: maven ... Signed-off-by: dependabot[bot] <support@github.com>
This was referenced Aug 12, 2026
Collaborator
|
Closing: this PR jumps past our Java 8 compatibility caps (e.g. Spring 6, Hibernate 6, CXF 4, ActiveMQ ≥5.17) that Tracked in #18; fix in #19 (multi-directory ignore application, invalid version-range cleanup, Java 8–safe groups). Please do not merge. After #19 lands, re-run Dependabot if needed — only Java 8–compatible updates should open. |
Collaborator
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
natechadwick
pushed a commit
that referenced
this pull request
Sep 17, 2026
…jquery-validation 1.22.1, browserstack-runner 0.9.4) (#246) * build(deps): bump io.netty:netty-* 4.1.136.Final -> 4.1.137.Final (CVE-2026-75595 + CVE-2026-75596) Dependabot alerts #169 (critical, CVE-2026-75595) and #168 (medium, CVE-2026-75596) on io.netty:netty-handler are closed by this bump. CVE-2026-75595 (critical, CVSS 9.1): SNI Routing Bypass via Fragmented TLS ClientHello. SslClientHelloHandler.decode checks the wrong offset for the handshake header guard; a fragmented ClientHello whose record header spans the 5-byte TLS record header + 4-byte handshake boundary silently falls back to the default SslContext. Per-SNI mTLS gates are bypassed. Fix in 4.1.137.Final + 4.2.17.Final. CVE-2026-75596 (medium, CVSS 6.9): Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing. With 4095 one-byte fragments the handler recopies 8,386,560 bytes from 24,579 bytes on the wire (341x amplification), exhausting the event-loop CPU before SslHandler takes over. Fix in 4.1.137.Final + 4.2.17.Final. Both CVEs have no Java 1.8 fix line below 4.1.137.Final; 4.1.137.Final is on the same 4.1.x line we already pin and is compiled for Java 6+ (class major version 50 verified on SslClientHelloHandler.class), so it is Java 1.8-compatible. Verification: ./mvn-env.sh dependency:tree -pl system -> netty-codec, netty-common, netty-handler, netty-resolver, netty-transport, netty-transport-classes-epoll, netty-transport-native-epoll, netty-transport-native-unix-common all resolved to 4.1.137.Final. ./mvn-env.sh test-compile -pl system -am -DskipTests -> BUILD SUCCESS. > Co-Authored by Mavis Mavis-Code using MiniMax-M3 with agent mavis. * build(deps): refresh web asset dependencies (lodash 4.18.1, requirejs 2.3.8, jquery-validation 1.22.1, browserstack-runner 0.9.4) Closes Dependabot alerts: #21, #17, #20 lodash CVE-2026-4800, CVE-2025-13465, CVE-2026-2950 #8 requirejs CVE-2024-38999 #1 jquery-validation CVE-2025-3573 #3, #2 browserstack-runner CVE-2026-49143, CVE-2026-49144 Changes: - cui/package.json + cui/package-lock.json: bump lodash >=4.17.21 -> ^4.18.1 and requirejs ^2.3.6 -> ^2.3.8. Regenerated the cui lockfile via 'npm install'. - WebUI/war/jslib/profiles/3x/jquery/plugins/jquery-validation/: replaced vendored jquery.validate.js + additional-methods.js + localization/ with the 1.22.1 release (closes CVE-2025-3573 XSS). Old per-language methods_*.js (de, es_CL, fi, it, nl, pt) were removed upstream in 1.20+ because the functionality moved to additional-methods.js core. - WebUI/war/jslib/profiles/3x/package.json: bump jquery-validation 1.19.5 -> 1.22.1 - cui/components/twitter-bootstrap-3.0.0/package.json: bump browserstack-runner ~0.0.12 -> ~0.9.4 (closes CVE-2026-49143 RCE + CVE-2026-49144 file-read). The browserstack-runner is only loaded by the vendored upstream Bootstrap Gruntfile.js for Travis CI tests on twbs/bootstrap; not used by the cms build. Verification: - npm install in cui/ completes with no peer-dep warnings that break the build. - All updated files resolve to the latest patched version. > Co-Authored by Mavis Mavis-Code using MiniMax-M3 with agent mavis.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the maven group with 12 updates in the / directory:
5.3.396.2.195.6.15.Final6.0.0.Final2.20.172.22.22.9.43.2.25.16.85.19.72.25.32.25.42.21.12.21.41.22.11.23.13.5.114.1.71.831.845.8.166.0.09.0.1179.0.118Bumps the maven group with 10 updates in the /projects/sitemanage directory:
5.3.396.2.195.6.15.Final6.0.0.Final2.20.172.22.22.9.43.2.25.16.85.19.72.25.32.25.42.21.12.21.41.22.11.23.13.5.114.1.71.831.84Bumps the maven group with 10 updates in the /system directory:
5.3.396.2.195.6.15.Final6.0.0.Final2.20.172.22.22.9.43.2.25.16.85.19.72.25.32.25.42.21.12.21.41.22.11.23.13.5.114.1.71.831.84Updates
org.springframework:spring-corefrom 5.3.39 to 6.2.19Release notes
Sourced from org.springframework:spring-core's releases.
... (truncated)
Commits
6214eaeRelease v6.2.1976a36dfTrack operations during SpEL expression evaluation3d47da9Ensure getters have non-void return types in SpEL519d733Improve additional error messages in SpELec89834Further improve pattern caching in SpELb294371Avoid too many character access attempts in AntPathMatcher1829b42Ensure consistent JSP tag attribute processing86d9979Refine JavaScriptUtils#javaScriptEscape3aaec98Prevent special prefixes in default view name resolutionee4e790Add trusted packages to MappingJackson2MessageConverterUpdates
org.springframework:spring-expressionfrom 5.3.39 to 6.2.19Release notes
Sourced from org.springframework:spring-expression's releases.
... (truncated)
Commits
6214eaeRelease v6.2.1976a36dfTrack operations during SpEL expression evaluation3d47da9Ensure getters have non-void return types in SpEL519d733Improve additional error messages in SpELec89834Further improve pattern caching in SpELb294371Avoid too many character access attempts in AntPathMatcher1829b42Ensure consistent JSP tag attribute processing86d9979Refine JavaScriptUtils#javaScriptEscape3aaec98Prevent special prefixes in default view name resolutionee4e790Add trusted packages to MappingJackson2MessageConverterUpdates
org.springframework:spring-webmvcfrom 5.3.39 to 6.2.19Release notes
Sourced from org.springframework:spring-webmvc's releases.
... (truncated)
Commits
6214eaeRelease v6.2.1976a36dfTrack operations during SpEL expression evaluation3d47da9Ensure getters have non-void return types in SpEL519d733Improve additional error messages in SpELec89834Further improve pattern caching in SpELb294371Avoid too many character access attempts in AntPathMatcher1829b42Ensure consistent JSP tag attribute processing86d9979Refine JavaScriptUtils#javaScriptEscape3aaec98Prevent special prefixes in default view name resolutionee4e790Add trusted packages to MappingJackson2MessageConverterUpdates
org.hibernate:hibernate-corefrom 5.6.15.Final to 6.0.0.FinalChangelog
Sourced from org.hibernate:hibernate-core's changelog.
... (truncated)
Commits
2560cc6Post-steps for release :6.0.0.Final53889dbPre-steps for release :6.0.0.Final6180e94- Drop building of bundles for SourceForgefa7cb3fFix issues with respecting padding and limit for in list renderingad828a0release announcement, doc artifacts8d20c03Address test failures in Gradle plugin module3358157HHH-15078 - Support for Tuple and SelectionQueryaa0c57aHHH-15078 - Support for Tuple and SelectionQuery88938acAddress test failures in Gradle plugin module5b0c49eHHH-15133 - Use specified result-type to better infer "shape" of query result...Updates
org.apache.jackrabbit:jackrabbit-jcr-commonsfrom 2.20.17 to 2.22.2Changelog
Sourced from org.apache.jackrabbit:jackrabbit-jcr-commons's changelog.
... (truncated)
Commits
2b5babf[maven-release-plugin] prepare release jackrabbit-2.22.20d7c2e5JCR-5180: Release Jackrabbit 2.22.2 - Candidate Release Notes (#277)b487b6fJCR-5158: Update oak-jackrabbit-api.version.implemented in trunk to Oak 1.82....52d8411JCR-5161: NamespaceHelper - get NamespaceRegistry only once (#259)6b6171eJCR-5150 Add constant for jcr:title02b09fdJCR-5159: Create coverage for NamespaceHelper (#256)0b81850JCR-5152 Add method to check if a (local) name is valid according to JCR2e64ea5JCR-5137: Update JCR commons to implement current jackrabbit-api (#231)9ba0518JCR-5089: avoid use of deprecated junit.framework.Assert (#208)019f6f9JCR-5177: jackrabbit-jcr2spi: update to commons-collections4 4.5.0 (#270)Updates
org.apache.tika:tika-corefrom 2.9.4 to 3.2.2Changelog
Sourced from org.apache.tika:tika-core's changelog.
... (truncated)
Commits
c5c9d00[maven-release-plugin] prepare release 3.2.2-rc15d87ef3update CHANGES.txt for 3.2.2 rc1a608cc2further improvements948c753TIKA-4455: update microsoft-graph, aws, nimbus0f78344TIKA-4455: update microsoft-graph94acef2Improve configuration of xmlinputfactory (#2294)0c89f4bSimplify path naming0b889d1TIKA-4455: update commons-clid20be6cTIKA-4455: replace deprecated8b580d8TIKA-4455: remove json-smart exclusion, no longer neededUpdates
org.apache.activemq:activemq-brokerfrom 5.16.8 to 5.19.7Release notes
Sourced from org.apache.activemq:activemq-broker's releases.
... (truncated)
Commits
fa56d21[maven-release-plugin] prepare release activemq-5.19.7038cb1eEnsure connection info is processed before durable sync (#2049)c3272deBackport network flaky test improvements (#2046)66efdf1[5.19.x] Harden web console and Jolokia access by default (#2025) (#2038)8cd761aHarden default broker and web console configuration (5.19.x backport) (#2036)647d318Bump dependencies to address known CVEs (#2031)4e49fbdRemove "java.lang" package as a default allowed serializable package (#2026) ...98d531c#2005 5.19.x - Fix authorization check on removeDestination (#2008)d82f61fDisable the message servlet by default (#2000) (#2015)c034ea8Handle validation for Composite URIs without parens (#2004) (#2013)Updates
org.apache.activemq:activemq-clientfrom 5.16.8 to 5.19.7Release notes
Sourced from org.apache.activemq:activemq-client's releases.