Skip to content

security: clear open Dependabot alerts (maven + npm pins, docs image overrides) - #1318

Merged
michalharakal merged 3 commits into
developfrom
security/dependabot-2026-10
Oct 9, 2026
Merged

michalharakal merged 3 commits into
developfrom
security/dependabot-2026-10

Conversation

@michalharakal

Copy link
Copy Markdown
Contributor

Clears 27 of the 29 open Dependabot alerts (2 critical, 11 high among them); the remaining 2 are extract-zip, which has no patched release.

Maven — plugin classpath (the two criticals live here)

sk.ainet.maven-pins now also constrains every project's buildscript configurations — that classpath is where the flagged libraries actually live (AGP ships BouncyCastle and commons-lang3, Kover ships FreeMarker, Dokka ships Jackson), and the existing configurations.all never reaches it. First pins declared:

Coordinate From → To Source Advisories
bcprov/bcpkix/bcutil-jdk18on 1.80.2 → 1.85 AGP GHSA-9pwp-9qqc-pr26 (critical), GHSA-qp49-qgx5-5m26, GHSA-c3fc-8qff-9hwx, GHSA-wg6q-6289-32hp
freemarker 2.3.32 → 2.3.35 Kover GHSA-27j2-h3m2-8237 (critical)
jackson core/databind/annotations 2.15.3 → 2.22.3 Dokka 9 GHSAs patched in 2.18.11
commons-lang3 3.16.0 → 3.18.0 AGP GHSA-j288-q9x7-2f5v
httpclient / jsoup / opentelemetry-api → 4.5.14 / 1.23.1 / 1.62.0 wherever resolved GHSA-7r82-7xv7-xcpj, GHSA-pmhh-3w7g-xqp8, GHSA-rcgg-9c38-7xpx

Jackson is pinned to the project's own audited 2.22.3 line (not the advisories' minimum 2.18.11) so the pin can never downgrade a project configuration; the three artifacts move together to stay version-aligned.

npm — kotlin-js-store/yarn.lock

fast-uri 3.1.7 → 3.1.8, brace-expansion 2.1.4 → 2.1.7, engine.io 6.6.9 → 6.6.10 (new JS-scoped pin). Lockfile regenerated via kotlinUpgradeYarnLock; follows up on #WIP fast-uri 3.1.7 which was one patch short of GHSA-hrr3-gc8f-f4qj.

docs image — npm overrides

basic-ftp 5.3.1 → 6.2.1 (high), dompurify 3.4.15 → 3.4.16. basic-ftp crosses a major, but its only consumer is get-uri's ftp: handler in puppeteer's proxy chain, which the docs build never exercises.

Not fixed

extract-zip 2.0.1 (2 high alerts): no patched release exists. Build-time only — @puppeteer/browsers uses it to unpack the Chrome archive from Google's CDN inside the docs image build. Suggest dismissing both alerts as no fix available with that rationale.

Verification

verifyMavenPins and verifyNpmPins pass across all subprojects; buildEnvironment confirms the buildscript classpath resolves every pinned coordinate to its patched version.

Maven (plugin classpath): extend sk.ainet.maven-pins to also constrain
every project's buildscript configurations — that classpath is where the
flagged libraries actually live, and configurations.all never reaches it.
First use of the mechanism pins:

- bouncycastle bcprov/bcpkix/bcutil 1.80.2 -> 1.85 (AGP; GHSA-9pwp-9qqc-pr26
  critical, GHSA-qp49-qgx5-5m26, GHSA-c3fc-8qff-9hwx, GHSA-wg6q-6289-32hp)
- freemarker 2.3.32 -> 2.3.35 (Kover; GHSA-27j2-h3m2-8237 critical)
- jackson core/databind/annotations 2.15.3 -> 2.22.3 (Dokka; nine
  GHSAs patched in 2.18.11; pinned to the project's own audited line so
  a project configuration can never be downgraded, all three artifacts
  together so the trio stays version-aligned)
- commons-lang3 3.16.0 -> 3.18.0 (AGP; GHSA-j288-q9x7-2f5v)
- httpclient -> 4.5.14 (GHSA-7r82-7xv7-xcpj), jsoup -> 1.23.1
  (GHSA-pmhh-3w7g-xqp8), opentelemetry-api -> 1.62.0
  (GHSA-rcgg-9c38-7xpx) wherever they appear

npm (kotlin-js-store/yarn.lock, regenerated via kotlinUpgradeYarnLock):

- fast-uri 3.1.7 -> 3.1.8 (GHSA-hrr3-gc8f-f4qj)
- brace-expansion 2.1.4 -> 2.1.7 (GHSA-6j4f-fj2g-mc7p,
  GHSA-qhr7-859c-m2p7, GHSA-q2hr-2g5m-vwhr)
- engine.io 6.6.9 -> 6.6.10, new JS-scoped pin (GHSA-2gc4-cqfq-p2gv)

verifyMavenPins and verifyNpmPins pass; buildEnvironment confirms the
buildscript classpath resolves every pinned coordinate to its patched
version.
basic-ftp 5.3.1 -> 6.2.1 (GHSA-c475-qrg2-pj4r, high) and dompurify
3.4.15 -> 3.4.16 (GHSA-p98j-92pf-mc4p) via npm overrides, same lever as
the existing js-yaml override; lockfile regenerated with
npm install --package-lock-only. basic-ftp crosses a major, but its
only consumer here is get-uri's ftp: handler inside puppeteer's proxy
chain, which the docs build never exercises.

extract-zip 2.0.1 (GHSA-7pqw-9j4j-h8q3, GHSA-jmr9-qjv8-65gv) stays: no
patched release exists. It is used by @puppeteer/browsers at image
build time to unpack the Chrome archive fetched from Google's CDN.
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

📖 Documentation Preview

The documentation has been built successfully for this PR.

Generated Files:

  • Operator documentation: docs/modules/operators/_generated_/
  • JSON schema output: operators.json

Artifacts:

  • Download the documentation-preview-1318 artifact to view the complete documentation locally.

This comment will be updated automatically when the PR is updated.

jackson-annotations has no patch releases (the 2.22 line is just
'2.22'), so pinning it to the databind version broke every Dokka
generator classpath with ModuleVersionNotFoundException (verify-poms
and build-docs CI jobs). databind's bom aligns annotations on its own:
the generator classpath now resolves annotations 2.22 next to
core/databind 2.22.3, and dokkaGeneratePublicationHtml runs clean.
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown

📖 Documentation Preview

The documentation has been built successfully for this PR.

Generated Files:

  • Operator documentation: docs/modules/operators/_generated_/
  • JSON schema output: operators.json

Artifacts:

  • Download the documentation-preview-1318 artifact to view the complete documentation locally.

This comment will be updated automatically when the PR is updated.

@michalharakal
michalharakal requested a review from aharakal October 5, 2026 15:12
@michalharakal
michalharakal merged commit af155bd into develop Oct 9, 2026
18 checks passed
@michalharakal
michalharakal deleted the security/dependabot-2026-10 branch October 9, 2026 16:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants