Skip to content

Fix vulnerable transitive dependencies - #36

Merged
arnabnandy7 merged 1 commit into
mainfrom
hotfix/vulnerabilityFix0.2
Sep 3, 2026
Merged

Fix vulnerable transitive dependencies#36
arnabnandy7 merged 1 commit into
mainfrom
hotfix/vulnerabilityFix0.2

Conversation

@arnabnandy7

Copy link
Copy Markdown
Owner

Summary

  • upgrade managed Netty dependencies to 4.2.17.Final
  • upgrade managed Log4j dependencies to 2.25.5
  • upgrade managed Jackson 3 dependencies to 3.1.5
  • add security-only Dependabot monitoring for Maven and GitHub Actions
  • group vulnerability updates into one PR per ecosystem

Security impact

Resolves the versions associated with the 15 currently open Dependabot alerts (6 high, 9 medium) after merge and dependency graph refresh.

Testing

  • mvn --batch-mode --no-transfer-progress clean test
  • Maven reactor: 6/6 modules successful
  • verified the resolved dependency tree uses the patched versions

@arnabnandy7 arnabnandy7 self-assigned this Sep 2, 2026
@arnabnandy7 arnabnandy7 added the dependencies Pull requests that update a dependency file label Sep 2, 2026
@sonarqubecloud

sonarqubecloud Bot commented Sep 2, 2026

Copy link
Copy Markdown

@arnabnandy7
arnabnandy7 merged commit c3af423 into main Sep 3, 2026
8 checks passed
@github-project-automation github-project-automation Bot moved this from WIP to Completed in BugDNA R&D Sep 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

Status: Completed

Development

Successfully merging this pull request may close these issues.

1 participant