Skip to content

Conversation

@aurbroszniowski
Copy link
Contributor

@aurbroszniowski aurbroszniowski commented Jan 23, 2026

Removed Gretty and used an embedded jetty 12 instance instead

TODO : the following vulnerable dependencies aren’t coming from the demos module:

Unknown
k8s.io/apimachinery:v0.24.2

SpotBug 4.2.3:
commons-text:1.9
gson:2.8.6

CheckStyle 8.45.1
commons-beanutils:1.9.3

@Gen-SIQA-User
Copy link
Collaborator

Gen-SIQA-User commented Jan 23, 2026

Checks Summary

Last run: 2026-01-23T17:24:53.765Z

Code Risk Analyzer vulnerability scan found 1 vulnerabilities:

Severity Identifier Package Details Fix
◻ Unknown CVE-2026-1225 ch.qos.logback:logback-core
Logback allows an attacker to instantiate classes already present on the class pathGHSA-qqpg-mvqg-649v

ch.qos.logback:logback-core:1.5.20->ch.qos.logback:logback-classic:1.5.20,org.terracotta:server-api:5.12.15,org.terracotta:galvan:5.12.15,org.terracotta.internal:galvan-support:5.12.15,org.terracotta:terracotta-dynamic-config-testing-galvan:5.11.6
1.5.25

@aurbroszniowski aurbroszniowski force-pushed the TDB-19854-upgrade-dependencies-main branch from 54dd9ae to 095df7b Compare January 23, 2026 17:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants