Update all non-major maven dependencies - #64
Closed
renovate[bot] wants to merge 1 commit into
Closed
Conversation
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## master #64 +/- ##
============================================
- Coverage 22.28% 20.27% -2.01%
+ Complexity 123 96 -27
============================================
Files 63 57 -6
Lines 920 878 -42
Branches 63 63
============================================
- Hits 205 178 -27
+ Misses 692 677 -15
Partials 23 23 ☔ View full report in Codecov by Sentry. |
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
from
March 23, 2024 18:50
88a067b to
8ea8075
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
from
April 11, 2024 11:45
8ea8075 to
446c482
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
from
April 27, 2024 14:20
446c482 to
f9008a3
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
2 times, most recently
from
May 11, 2024 11:19
8bd7950 to
bd7dbcb
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
2 times, most recently
from
May 22, 2024 17:06
cbf8e40 to
52af3a8
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
2 times, most recently
from
June 14, 2024 16:49
63897bc to
342b03d
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
from
June 28, 2024 01:32
342b03d to
6a8bc1f
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
5 times, most recently
from
July 11, 2024 09:58
b82b7f7 to
629bf06
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
4 times, most recently
from
July 22, 2024 15:47
baa22ce to
8647f24
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
3 times, most recently
from
July 25, 2024 06:00
5c74bdf to
cf7d9c7
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
2 times, most recently
from
August 14, 2024 12:26
d4b3a2f to
dce981f
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
3 times, most recently
from
August 22, 2024 20:37
3b83894 to
a88ecd7
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
from
August 27, 2024 14:37
a88ecd7 to
fe89db5
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
2 times, most recently
from
November 22, 2024 01:31
ccd6884 to
f7eb69a
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
2 times, most recently
from
December 3, 2024 01:22
fddff02 to
aa91422
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
from
December 19, 2024 16:42
aa91422 to
1da5f8e
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
2 times, most recently
from
January 10, 2025 18:47
f335772 to
28ea707
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
from
January 16, 2025 09:45
28ea707 to
4543ec0
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
2 times, most recently
from
January 27, 2025 20:40
e682c20 to
7b71206
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
from
February 2, 2025 12:41
7b71206 to
165d4b8
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
from
February 13, 2025 16:23
165d4b8 to
ae54a67
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
from
February 20, 2025 19:10
ae54a67 to
3c3f2a0
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
from
March 1, 2025 01:54
3c3f2a0 to
635c6c4
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
3 times, most recently
from
March 21, 2025 05:46
cd0bf7e to
36aa1e5
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
3 times, most recently
from
March 31, 2025 15:47
c1bce2a to
522cf0d
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
2 times, most recently
from
April 17, 2025 11:58
1b0ffe9 to
cf1d843
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
4 times, most recently
from
April 29, 2025 00:10
9562d43 to
7df5545
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
2 times, most recently
from
May 16, 2025 16:00
5d61ff5 to
80198e4
Compare
renovate
Bot
force-pushed
the
renovate/all-maven-minor-patch
branch
from
May 22, 2025 21:13
80198e4 to
056adf0
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.1.1→3.2.05.3.1→5.64.0.0→4.0.72.1.0→2.1.44.0.0→4.0.51.18.32→1.18.441.9.7→1.9.25.12.4.3→2.5.41.15→1.21.03.18.0→3.20.02.17.1→2.18.62.17.1→2.21.22.17.1→2.21.23.3.1→3.5.123.3.1→3.3.116.1.10→6.1.216.1.10→6.2.17GitHub Vulnerability Alerts
GHSA-72hv-8253-57qq
Summary
The non-blocking (async) JSON parser in
jackson-corebypasses themaxNumberLengthconstraint (default: 1000 characters) defined inStreamReadConstraints. This allows an attacker to send JSON with arbitrarily long numbers through the async parser API, leading to excessive memory allocation and potential CPU exhaustion, resulting in a Denial of Service (DoS).The standard synchronous parser correctly enforces this limit, but the async parser fails to do so, creating an inconsistent enforcement policy.
Details
The root cause is that the async parsing path in
NonBlockingUtf8JsonParserBase(and related classes) does not call the methods responsible for number length validation._finishNumberIntegralPart) accumulate digits into theTextBufferwithout any length checks._valueComplete(), which finalizes the token but does not callresetInt()orresetFloat().resetInt()/resetFloat()methods inParserBaseare where thevalidateIntegerLength()andvalidateFPLength()checks are performed.maxNumberLengthconstraint is never enforced in the async code path.PoC
The following JUnit 5 test demonstrates the vulnerability. It shows that the async parser accepts a 5,000-digit number, whereas the limit should be 1,000.
Impact
A malicious actor can send a JSON document with an arbitrarily long number to an application using the async parser (e.g., in a Spring WebFlux or other reactive application). This can cause:
TextBufferto store the number's digits, leading to anOutOfMemoryError.getBigIntegerValue()orgetDecimalValue(), the JVM can be tied up in O(n^2)BigIntegerparsing operations, leading to a CPU-based DoS.Suggested Remediation
The async parsing path should be updated to respect the
maxNumberLengthconstraint. The simplest fix appears to ensure that_valueComplete()or a similar method in the async path calls the appropriate validation methods (resetInt()orresetFloat()) already present inParserBase, mirroring the behavior of the synchronous parsers.NOTE: This research was performed in collaboration with rohan-repos
CVE-2025-22235
EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not exposed.
Your application may be affected by this if all the following conditions are met:
You are not affected if any of the following is true:
CVE-2024-38809
Description
Applications that parse ETags from
If-MatchorIf-None-Matchrequest headers are vulnerable to DoS attack.Affected Spring Products and Versions
org.springframework:spring-web in versions
6.1.0 through 6.1.11
6.0.0 through 6.0.22
5.3.0 through 5.3.37
Older, unsupported versions are also affected
Mitigation
Users of affected versions should upgrade to the corresponding fixed version.
6.1.x -> 6.1.12
6.0.x -> 6.0.23
5.3.x -> 5.3.38
No other mitigation steps are necessary.
Users of older, unsupported versions could enforce a size limit on
If-MatchandIf-None-Matchheaders, e.g. through a Filter.CVE-2024-38820
The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
CVE-2025-41234
Description
In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when it sets a “Content-Disposition” header with a non-ASCII charset, where the filename attribute is derived from user-supplied input.
Specifically, an application is vulnerable when all the following are true:
org.springframework.http.ContentDisposition.ContentDisposition.Builder#filename(String, Charset).An application is not vulnerable if any of the following is true:
org.springframework.http.ContentDisposition.ContentDisposition.Builder#filename(String), orContentDisposition.Builder#filename(String, ASCII)Affected Spring Products and VersionsSpring Framework
Mitigation
Users of affected versions should upgrade to the corresponding fixed version.
No further mitigation steps are necessary.
Release Notes
spring-projects/spring-vault (org.springframework.vault:spring-vault-core)
v3.2.0Compare Source
📗 Links
⭐ New Features
KeyValueDelegate.getMountInfo(…)fails #888PredicatetoSecretLeaseContainerto determine whether aLeaseis expired #809🐞 Bug Fixes
KeyValueDelegatecaches empty path during Vault unavailability #889nullinCertificateBundleusingof(String serialNumber, String certificate, String issuingCaCertificate, String privateKey)#857SecretLeaseContainer#844📔 Documentation
🔨 Dependency Upgrades
❤️ Contributors
We'd like to thank all the contributors who worked on this release!
v3.1.3Compare Source
📗 Links
⭐ New Features
KeyValueDelegate.getMountInfo(…)fails #888🐞 Bug Fixes
KeyValueDelegatecaches empty path during Vault unavailability #889🔨 Dependency Upgrades
❤️ Contributors
We'd like to thank all the contributors who worked on this release!
v3.1.2Compare Source
📗 Links
🐞 Bug Fixes
nullinCertificateBundleusingof(String serialNumber, String certificate, String issuingCaCertificate, String privateKey)#857📔 Documentation
🔨 Dependency Upgrades
❤️ Contributors
We'd like to thank all the contributors who worked on this release!
apache/httpcomponents-client (org.apache.httpcomponents.client5:httpclient5)
v5.6This is the first ALPHA release in the 5.6 release series. It adds several features
such as transport content decompression and content compression for the async transport,
support for Unix sockets, experimental support for SCRAM-SHA-256 authentication scheme,
and Micrometer/OTel observations & metrics.
Commons Compress, Brotli codec, and ZStd codec are optional dependencies and get
wired into the execution pipeline only if present on the classpath.
Notable changes and features included in the 5.6 series:
Unix domain socket support.
Support for pluggable content codecs via Commons-Compress in the classic transport.
(optional).
Support for transparent content decompression and content compression with
deflate,gzip,zstd(optional), andbrotli(optional) codecs in the async transport.Micrometer/OTel observations & metrics (optinal).
Off-lock connection disposal by the classic pooling connection manager. Experimental.
SCRAM-SHA-256 authentication scheme (RFC 7804). Experimental.
Request Priority support (RFC 9218). Experimental.
Compatibility notes:
As of this version, HttpClient uses BUILTIN HostnameVerificationPolicy by default, delegating
host verification to JSSE security manager. One must explicitly configure the TLS strategy
to continue using the hostname verifier shipped with HttpClient.
Five-second TCP keep-alive is now enabled by default.
v5.5This is the first GA release in the 5.5 release series. This release finalizes the 5.5
APIs and adds several experimental features and improvements, such as request multiplexing
over a shared HTTP/2 connection and the Classic API facade acting as a compatibility
bridge between classic I/O client services and the asynchronous message transport used
internally.
Notable changes and features included in the 5.5 series:
Improved conformance to RFC 7616 (HTTP Digest Access Authentication).
The connection pool implementation acts as a caching facade in front of a standard
managed connection pool and shares already leased connections to multiplex message
exchanges over active HTTP/2 connections. Experimental.
Extended Auth API and improved authentication protocol logic to support mutual
authentication.
The Classic API facade now acts as a compatibility bridge between the classic I/O client
services (based on the standard InputStream / OutputStream model) and the asynchronous
message transport used internally. This is experimental.
HTTP/2 support for the Fluent Facade (via Classic API facade). This is experimental.
Compatibility notes:
request manually added headers that are considered sensitive.
v5.4This is the first GA release in the 5.4 release series. This release finalizes the 5.4 APIs,
upgrades HttpCore to version 5.3 and improves the Public Suffix matching algorithm implementation.
IMPORTANT! The new cache entry serialization format is incompatible with earlier
versions of HttpClient Cache. Persistent caches (file system based, Memcached, EhCAche
with object serialization) created with any earlier version MUST be flushed and re-populated
or the cache backend MUST be configured to use the old, deprecated cache entry serializer.
Notable changes and features included in the 5.4 series:
Improved conformance to RFC 9110 (HTTP Semantics), RFC 7616 (HTTP Digest Access
Authentication), RFC 2617 (’Basic’ HTTP Authentication Scheme).
UTF-8 encoding is used by default for text where appropriate.
Compatibility with Java Virtual Threads and Java 21 Runtime.
Redesign and rewrite of the HTTP caching protocol layer for better efficiency
and improved conformance to RFC 9111 (HTTP Caching).
Cache control and context APIs.
ETag APIs.
TLS SNI and endpoint identification improvements.
Support for RFC 2817 (Upgrading to TLS Within HTTP/1.1).
Auth cache no longer makes use of Java serialization.
Deprecation of ConnectionSocketFactory and LayeredConnectionSocketFactory.
HttpContext optimization and performance improvement.
Async cache is no longer considered experimental.
jakartaee/jaf-api (jakarta.activation:jakarta.activation-api)
v2.1.4Compare Source
v2.1.3: Jakarta Activation 2.1.3 Final ReleaseCompare Source
The 2.1.3 release is a bug fix release of 2.1.x (Jakarta EE 10).
Following changes are included:
Thread.getContextClassLoaderFull Changelog: jakartaee/jaf-api@2.1.2...2.1.3
v2.1.2: Jakarta Activation 2.1.2 Final ReleaseCompare Source
The 2.1.2 release is a bug fix release of 2.1.x (Jakarta EE 10).
Following changes are included:
Full Changelog: jakartaee/jaf-api@2.1.1...2.1.2
v2.1.1: Jakarta Activation 2.1.1 Final ReleaseCompare Source
The 2.1.1 release is a bug fix release of 2.1.0.
Following changes are included:
New Contributors
Full Changelog: jakartaee/jaf-api@2.1.0...2.1.1
jakartaee/jaxb-api (jakarta.xml.bind:jakarta.xml.bind-api)
v4.0.5: Jakarta XML Binding API 4.0.5Compare Source
What's Changed
Full Changelog: jakartaee/jaxb-api@4.0.4...4.0.5
v4.0.4: Jakarta XML Binding API 4.0.4Compare Source
What's Changed
New Contributors
Full Changelog: jakartaee/jaxb-api@4.0.3...4.0.4
v4.0.3: Jakarta XML Binding API 4.0.3Compare Source
What's Changed
nullby @netmikey in #313New Contributors
Full Changelog: jakartaee/jaxb-api@4.0.2...4.0.3
v4.0.2: Jakarta XML Binding API 4.0.2Compare Source
The 4.0.2 release is a bug fix release of 4.0.0.
Following changes are included:
New Contributors
Full Changelog: jakartaee/jaxb-api@4.0.1...4.0.2
v4.0.1: Jakarta XML Binding API 4.0.1Compare Source
The 4.0.1 release is a bug fix release of 4.0.0.
Following changes are included:
New Contributors
Full Changelog: jakartaee/jaxb-api@4.0.0...4.0.1
projectlombok/lombok (org.projectlombok:lombok)
v1.18.44v1.18.42Compare Source
v1.18.40Compare Source
v1.18.38Compare Source
v1.18.36Compare Source
v1.18.34datafaker-net/datafaker (net.datafaker:datafaker)
v2.5.4Compare Source
What's Changed
New Contributors
Full Changelog: datafaker-net/datafaker@2.5.3...2.5.4
v2.5.3Compare Source
What's Changed
New Contributors
Full Changelog: datafaker-net/datafaker@2.5.2...2.5.3
v2.5.2Compare Source
What's Changed
New Contributors
Full Changelog: datafaker-net/datafaker@2.5.1...2.5.2
v2.5.1Compare Source
What's Changed
faker.text().text(1, 64, true, false, true)by @asolntsev in #1660New Contributors
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.