Repository navigation
security: clear open Dependabot alerts (maven + npm pins, docs image overrides) - #1318
Merged
Merged
Conversation
Maven (plugin classpath): extend sk.ainet.maven-pins to also constrain every project's buildscript configurations — that classpath is where the flagged libraries actually live, and configurations.all never reaches it. First use of the mechanism pins: - bouncycastle bcprov/bcpkix/bcutil 1.80.2 -> 1.85 (AGP; GHSA-9pwp-9qqc-pr26 critical, GHSA-qp49-qgx5-5m26, GHSA-c3fc-8qff-9hwx, GHSA-wg6q-6289-32hp) - freemarker 2.3.32 -> 2.3.35 (Kover; GHSA-27j2-h3m2-8237 critical) - jackson core/databind/annotations 2.15.3 -> 2.22.3 (Dokka; nine GHSAs patched in 2.18.11; pinned to the project's own audited line so a project configuration can never be downgraded, all three artifacts together so the trio stays version-aligned) - commons-lang3 3.16.0 -> 3.18.0 (AGP; GHSA-j288-q9x7-2f5v) - httpclient -> 4.5.14 (GHSA-7r82-7xv7-xcpj), jsoup -> 1.23.1 (GHSA-pmhh-3w7g-xqp8), opentelemetry-api -> 1.62.0 (GHSA-rcgg-9c38-7xpx) wherever they appear npm (kotlin-js-store/yarn.lock, regenerated via kotlinUpgradeYarnLock): - fast-uri 3.1.7 -> 3.1.8 (GHSA-hrr3-gc8f-f4qj) - brace-expansion 2.1.4 -> 2.1.7 (GHSA-6j4f-fj2g-mc7p, GHSA-qhr7-859c-m2p7, GHSA-q2hr-2g5m-vwhr) - engine.io 6.6.9 -> 6.6.10, new JS-scoped pin (GHSA-2gc4-cqfq-p2gv) verifyMavenPins and verifyNpmPins pass; buildEnvironment confirms the buildscript classpath resolves every pinned coordinate to its patched version.
basic-ftp 5.3.1 -> 6.2.1 (GHSA-c475-qrg2-pj4r, high) and dompurify 3.4.15 -> 3.4.16 (GHSA-p98j-92pf-mc4p) via npm overrides, same lever as the existing js-yaml override; lockfile regenerated with npm install --package-lock-only. basic-ftp crosses a major, but its only consumer here is get-uri's ftp: handler inside puppeteer's proxy chain, which the docs build never exercises. extract-zip 2.0.1 (GHSA-7pqw-9j4j-h8q3, GHSA-jmr9-qjv8-65gv) stays: no patched release exists. It is used by @puppeteer/browsers at image build time to unpack the Chrome archive fetched from Google's CDN.
|
📖 Documentation Preview The documentation has been built successfully for this PR. Generated Files:
Artifacts:
This comment will be updated automatically when the PR is updated. |
jackson-annotations has no patch releases (the 2.22 line is just '2.22'), so pinning it to the databind version broke every Dokka generator classpath with ModuleVersionNotFoundException (verify-poms and build-docs CI jobs). databind's bom aligns annotations on its own: the generator classpath now resolves annotations 2.22 next to core/databind 2.22.3, and dokkaGeneratePublicationHtml runs clean.
|
📖 Documentation Preview The documentation has been built successfully for this PR. Generated Files:
Artifacts:
This comment will be updated automatically when the PR is updated. |
aharakal
approved these changes
Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Clears 27 of the 29 open Dependabot alerts (2 critical, 11 high among them); the remaining 2 are extract-zip, which has no patched release.
Maven — plugin classpath (the two criticals live here)
sk.ainet.maven-pinsnow also constrains every project's buildscript configurations — that classpath is where the flagged libraries actually live (AGP ships BouncyCastle and commons-lang3, Kover ships FreeMarker, Dokka ships Jackson), and the existingconfigurations.allnever reaches it. First pins declared:Jackson is pinned to the project's own audited 2.22.3 line (not the advisories' minimum 2.18.11) so the pin can never downgrade a project configuration; the three artifacts move together to stay version-aligned.
npm — kotlin-js-store/yarn.lock
fast-uri 3.1.7 → 3.1.8, brace-expansion 2.1.4 → 2.1.7, engine.io 6.6.9 → 6.6.10 (new JS-scoped pin). Lockfile regenerated via
kotlinUpgradeYarnLock; follows up on #WIP fast-uri 3.1.7 which was one patch short of GHSA-hrr3-gc8f-f4qj.docs image — npm overrides
basic-ftp 5.3.1 → 6.2.1 (high), dompurify 3.4.15 → 3.4.16. basic-ftp crosses a major, but its only consumer is get-uri's
ftp:handler in puppeteer's proxy chain, which the docs build never exercises.Not fixed
extract-zip 2.0.1 (2 high alerts): no patched release exists. Build-time only — @puppeteer/browsers uses it to unpack the Chrome archive from Google's CDN inside the docs image build. Suggest dismissing both alerts as no fix available with that rationale.
Verification
verifyMavenPinsandverifyNpmPinspass across all subprojects;buildEnvironmentconfirms the buildscript classpath resolves every pinned coordinate to its patched version.