Skip to content

Fix Security Violation#47

Open
agrasth wants to merge 1 commit intomainfrom
violationFix
Open

Fix Security Violation#47
agrasth wants to merge 1 commit intomainfrom
violationFix

Conversation

@agrasth
Copy link
Copy Markdown
Contributor

@agrasth agrasth commented Mar 13, 2026

Title: Fix security audit violations - upgrade build-info, add commons-* overrides, fix SAST

Description:
Upgrade vulnerable direct dependencies and fix SAST findings.

  • build-info-extractor: 2.41.22 → 2.43.6
  • commons-io: added override at 2.18.0
  • commons-lang3: added override at 3.18.0
  • ehcache: added override at 2.10.9.2
  • Fixed SAST finding in JfrogServerConfigAction.java (unencrypted HTTP warning)

Remaining CVEs are in Bamboo framework (scope provided) and require Xray policy adjustment.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant