Resolve security vulnerabilities in Jackson and Central publishing plugin dependencies#458
Merged
frankgiordano merged 8 commits intomainfrom Mar 30, 2026
Merged
Resolve security vulnerabilities in Jackson and Central publishing plugin dependencies#458frankgiordano merged 8 commits intomainfrom
frankgiordano merged 8 commits intomainfrom
Conversation
Signed-off-by: Frank Giordano <giofr01@yahoo.com>
Signed-off-by: Frank Giordano <giofr01@yahoo.com>
Signed-off-by: Frank Giordano <giofr01@yahoo.com>
Signed-off-by: Frank Giordano <giofr01@yahoo.com>
Signed-off-by: Frank Giordano <giofr01@yahoo.com>
Improve error handling by providing more context in the exception message when parsing the TSO start response fails. Signed-off-by: Frank Giordano <giofr01@yahoo.com>
Signed-off-by: Frank Giordano <giofr01@yahoo.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This PR addresses two dependency-related security issues identified by scanning tools.
See #456
Updated the Unirest Jackson integration dependency to a newer version in order to pull in a patched Jackson stack and resolve the reported vulnerability tied to the previous Jackson-based dependency chain.
Updated dependency:
See #457
Resolved the vulnerability associated with plexus-utils, which was being introduced through central-publishing-maven-plugin.
Changes made:
Removed central-publishing-maven-plugin from the main section since it is a build plugin, not a runtime dependency
Upgraded the plugin version in the ci-cd profile
Added an explicit plugin dependency override for a patched plexus-utils version
Summary of Changes
Impact
Notes
A JSON parsing test failure surfaced after the Jackson-related upgrade which code changes made to handle it.