Skip to content

Bump com.diffplug.spotless:spotless-maven-plugin from 2.43.0 to 3.10.0 - #17

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/com.diffplug.spotless-spotless-maven-plugin-3.10.0
Open

Bump com.diffplug.spotless:spotless-maven-plugin from 2.43.0 to 3.10.0#17
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/com.diffplug.spotless-spotless-maven-plugin-3.10.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown

Bumps com.diffplug.spotless:spotless-maven-plugin from 2.43.0 to 3.10.0.

Release notes

Sourced from com.diffplug.spotless:spotless-maven-plugin's releases.

Maven Plugin v3.10.0

Added

  • New <shortenFullyQualifiedTypes> step for Java, which replaces fully-qualified type names with their simple names and adds the imports they need. Best combined with <importOrder> and <removeUnusedImports>. (#2945)
  • Add embedded lockfiles to Eclipse JDT for every supported version (4.9 through 4.40), so eclipse() resolves from Maven Central instead of querying a P2 update site. Versions without an embedded lockfile still fall back to P2 provisioning. (#1996)
  • Add support to apply alternate license header within same format (#872)
  • Add support to skip license header application based on source file content pattern (#650).

Fixed

  • removeUnusedImports no longer fails on Java import module declarations. (#2890)
  • Concurrent P2 provisioning no longer races Solstice's on-disk cache (affects Eclipse-based formatters under parallel builds). (#3004)

Changes

  • Default google-java-format remains 1.28.0 on JVM 17; bumps to 1.30.0 on JVM 21+; require at least 1.30.0 on JVM 25+ for import module support.
  • Bump default eclipse version to latest 4.39 -> 4.40. (#1996)
  • Document Maven skip properties spotless.skip, spotless.check.skip, and spotless.apply.skip. Goal-specific skips now live on their own mojos so they no longer leak across goals. (#3009)
  • Bump default adocfmt version 0.2.0 -> 0.3.1, which adds table formatting support (<formatTables>, <tableLayout>, <tableMaxLineWidth>, <tableBlankLines>).

Maven Plugin v3.9.0

Added

Changes

  • Replace RDF formatter library de.atextor:turtle-formatter (discontinued) with cool.rdf:cool-rdf-formatter (its new coordinates); the RDF/turtle formatter now requires Java 25+. (#2995)
  • Bump default greclipse version to latest 4.39 -> 4.40. (#2989)
  • Bump default tabletest-formatter version 1.1.1 -> 1.1.2.

Maven Plugin v3.8.0

Added

  • Add support for custom string format for license header copyright year via yearStringFormat(). (#2965)

Fixed

  • <expandWildcardImports> no longer triggers a full transitive dependency resolution on every build. Dependency resolution is now deferred until the step actually runs, so projects that do not use <expandWildcardImports> (or that use version ranges) are no longer penalized. (#2983)

Maven Plugin v3.7.0

Fixed

  • Parse standard git year output in LicenseHeaderStep. (#2940)
  • <toggleOffOn> no longer disables lint-only steps such as <forbidWildcardImports>. (#2962)
  • Fix StringIndexOutOfBoundsException in scenarios where copyright year is surrounded by whitespace. (#2973)

Added

  • Add support for AsciiDoc formatting via adocfmt. (#2960)
  • <flexmark> step now supports arbitrary formatter options via <formatterOptions>. (#2968)

Maven Plugin v3.6.0

Added

  • Add <cacheDirectory> to <eclipse>, <greclipse>, and <eclipseCdt> for the Equo/Solstice P2 cache. (#2944)
  • EclipseJdtFormtterStep now can conditionally set compiler source/compliance options. Allows for better parsing of AST Node for newer language features and more correct sorting; e.g. records or seal classes. (#2942)

Fixed

  • <versionCatalog> no longer splits long inline tables across multiple lines — Gradle's TOML 1.0 parser cannot read multi-line inline tables. The maxLineLength option has been removed. (#2948)
  • spotless:apply no longer aborts on the first file with lints; it now formats all files and reports a single aggregated lint failure across every file, matching the Gradle plugin's behavior. (#2937)
  • <greclipse> and <eclipseCdt> now default P2 data to the Maven local repository. (#2944)
  • forbidWildcardImports and forbidModuleImports now detect imports that have leading whitespace (indentation/tabs). (#2939)

Changes

  • Improved formatting performance by eliminating redundant per-step line-ending normalization in the core formatter loop. (#2934)

... (truncated)

Changelog

Sourced from com.diffplug.spotless:spotless-maven-plugin's changelog.

spotless-lib and spotless-lib-extra releases

If you are a Spotless user (as opposed to developer), then you are probably looking for:

This document is intended for Spotless developers.

We adhere to the keepachangelog format (starting after version 1.27.0).

[Unreleased]

[4.10.1] - 2026-08-27

Fixed

  • Prettier and other npm-based formatters no longer fail to start on npm 12 (EUNKNOWNCONFIG from --scripts-prepend-node-path). (#3024)

[4.10.0] - 2026-08-17

Added

  • New ShortenFullyQualifiedTypesStep for Java, which replaces fully-qualified type names with their simple names and adds the imports they need. Uses JavaParser to find type references in the AST, so occurrences in strings, comments, and other non-type contexts are left alone. (#2945)
  • Add embedded lockfiles to Eclipse JDT for every supported version (4.9 through 4.40), so eclipse() resolves from Maven Central instead of querying a P2 update site. Versions without an embedded lockfile still fall back to P2 provisioning. (#1996)

Fixed

  • removeUnusedImports no longer throws on Java import module declarations (JCModuleImport ClassCastException). (#2890)
  • Concurrent P2 provisioning (parallel multi-project Gradle fingerprinting of eclipse() / greclipse() steps) no longer races Solstice's on-disk cache; also ConfigurationCacheHackList.toString() no longer evaluates step state (which could re-trigger provisioning while Gradle reports "cannot be serialized"). (#3004)

Changes

  • Default google-java-format remains 1.28.0 on JVM 17; bumps to 1.30.0 on JVM 21+; require at least 1.30.0 on JVM 25+ for import module support.
  • Bump default eclipse version to latest 4.39 -> 4.40. (#1996)
  • Bump default adocfmt version 0.2.0 -> 0.3.1, which adds table formatting support (formatTables, tableLayout, tableMaxLineWidth, tableBlankLines).

[4.9.0] - 2026-07-27

Added

Changes

  • Replace RDF formatter library de.atextor:turtle-formatter (discontinued) with cool.rdf:cool-rdf-formatter (its new coordinates); the RDF/turtle formatter now requires Java 25+. (#2995)
  • Bump default greclipse version to latest 4.39 -> 4.40. (#2989)
  • Bump default tabletest-formatter version 1.1.1 -> 1.1.2.

[4.8.0] - 2026-06-29

Added

  • Add support for custom string format for license header copyright year via yearStringFormat(). (#2965)

[4.7.0] - 2026-06-16

Added

  • Add support for AsciiDoc formatting via adocfmt. (#2960)
  • flexmark step now supports arbitrary formatter options via a formatterOptions map. (#2968)

Fixed

  • FenceStep.preserveWithin now forwards lints from nested steps while still suppressing lints inside preserved blocks. (#2962)
  • Support ktfmt 0.63 and use its new builder API for formatting options to better avoid future breaking changes.
  • Parse standard git year output in LicenseHeaderStep. (#2940)
  • Fix StringIndexOutOfBoundsException in scenarios where copyright year is surrounded by whitespace. (#2973)

... (truncated)

Commits
  • 426b21d Published maven/3.10.0
  • 2fd42ea Published gradle/8.10.0
  • d71ed1a Published lib/4.10.0
  • 8b57c01 Add shortenFullyQualifiedTypes step (fixes #2945) (#3005 closes #2945)
  • 6b42c5e fix: make the FQN-collecting visitor a named static class
  • 4430823 Better organization on the changelogs.
  • 45bea6d Better place to put the shortenFullyQualifiedTypes docs
  • 0c49e65 chore: spotlessApply
  • 1c5bc0a docs: list the Java import steps in the plugin README tables of contents
  • cd57b58 docs: document shortenFullyQualifiedTypes in the plugin READMEs
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [com.diffplug.spotless:spotless-maven-plugin](https://github.com/diffplug/spotless) from 2.43.0 to 3.10.0.
- [Release notes](https://github.com/diffplug/spotless/releases)
- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)
- [Commits](diffplug/spotless@lib/2.43.0...maven/3.10.0)

---
updated-dependencies:
- dependency-name: com.diffplug.spotless:spotless-maven-plugin
  dependency-version: 3.10.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies java Pull requests that update java code labels Sep 2, 2026
@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown

Mend Scan Results

Status: ⚠️ Findings detected

⚠️ SCA findings detected

SCA scan output



Identified 244 dependencies

Detected 39 vulnerabilities (4 Critical, 14 High, 21 Medium, 0 Low)

+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| SEVERITY |               LIBRARY               |       ID       |                                               TOP FIX                                                |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| CRITICAL | bcprov-jdk18on-1.84.jar             | CVE-2026-58062 | Upgrade to version org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcprov-lts8on:2.73.12,            |
|          |                                     |                | org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-jdk18on:1.85,                                 |
|          |                                     |                | org.bouncycastle:bcprov-jdk15to18:1.85, https://github.com/bcgit/bc-java.git - r1rv85                |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| CRITICAL | bcprov-jdk18on-1.84.jar             | CVE-2026-59650 | Upgrade to version org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,    |
|          |                                     |                | org.bouncycastle:bcprov-jdk18on:1.85, https://github.com/bcgit/bc-java.git - r1rv85                  |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| CRITICAL | bcprov-jdk18on-1.84.jar             | CVE-2026-8763  | Upgrade to version org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-jdk15to18:1.85,      |
|          |                                     |                | org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bc-fips:2.1.3,                                     |
|          |                                     |                | org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bc-fips:2.0.2,                               |
|          |                                     |                | https://github.com/bcgit/bc-java.git - r1rv85                                                        |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| CRITICAL | netty-handler-4.1.136.Final.jar     | CVE-2026-75595 | Upgrade to version io.netty:netty-handler:4.2.17.Final,io.netty:netty-handler:4.1.137.Final,         |
|          |                                     |                | https://github.com/netty/netty.git - netty-4.1.137.Final, https://github.com/netty/netty.git -       |
|          |                                     |                | netty-4.2.17.Final                                                                                   |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | bcpkix-jdk18on-1.84.jar             | CVE-2026-12802 | Upgrade to version org.bouncycastle:bcpkix-lts8on:2.73.12,org.bouncycastle:bcpkix-fips:2.1.12,       |
|          |                                     |                | org.bouncycastle:bcpkix-jdk18on:1.85,org.bouncycastle:bcpkix-fips:1.0.12,                            |
|          |                                     |                | org.bouncycastle:bcpkix-fips:2.0.12,org.bouncycastle:bcpkix-jdk15to18:1.85,                          |
|          |                                     |                | https://github.com/bcgit/bc-java.git - r1rv85                                                        |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | bcpkix-jdk18on-1.84.jar             | CVE-2026-59639 | Upgrade to version org.bouncycastle:bcpkix-jdk18on:1.85,org.bouncycastle:bcpkix-lts8on:2.73.12,      |
|          |                                     |                | org.bouncycastle:bcpkix-fips:1.0.12,org.bouncycastle:bcpkix-jdk15to18:1.85,                          |
|          |                                     |                | org.bouncycastle:bcpkix-fips:2.1.12,org.bouncycastle:bcpkix-fips:2.0.12,                             |
|          |                                     |                | https://github.com/bcgit/bc-java.git - r1rv85                                                        |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | bcpkix-jdk18on-1.84.jar             | CVE-2026-59642 | Upgrade to version org.bouncycastle:bcpkix-fips:1.0.12,org.bouncycastle:bcpkix-fips:2.0.12,          |
|          |                                     |                | org.bouncycastle:bcpkix-jdk15to18:1.85,org.bouncycastle:bcpkix-fips:2.1.12,                          |
|          |                                     |                | org.bouncycastle:bcpkix-jdk18on:1.85,org.bouncycastle:bcpkix-lts8on:2.73.12,                         |
|          |                                     |                | https://github.com/bcgit/bc-java.git - r1rv85                                                        |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | bcprov-jdk18on-1.84.jar             | CVE-2026-12803 | Upgrade to version org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,      |
|          |                                     |                | org.bouncycastle:bcprov-lts8on:2.73.12, https://github.com/bcgit/bc-java.git - r1rv85                |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | bcprov-jdk18on-1.84.jar             | CVE-2026-12816 | Upgrade to version org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,    |
|          |                                     |                | org.bouncycastle:bcprov-jdk18on:1.85, https://github.com/bcgit/bc-java.git - r1rv85                  |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | bcprov-jdk18on-1.84.jar             | CVE-2026-12860 | Upgrade to version org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,      |
|          |                                     |                | org.bouncycastle:bcprov-jdk15to18:1.85, https://github.com/bcgit/bc-java.git - r1rv85                |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | bcprov-jdk18on-1.84.jar             | CVE-2026-13506 | Upgrade to version org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bc-fips:2.0.2,            |
|          |                                     |                | org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bcprov-jdk18on:1.85 |
|          |                                     |                | ,org.bouncycastle:bcprov-jdk15to18:1.85, https://github.com/bcgit/bc-java.git - r1rv85               |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | bcprov-jdk18on-1.84.jar             | CVE-2026-14682 | Upgrade to version org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-jdk18on:1.85,              |
|          |                                     |                | org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bc-fips:2.0.2,                                     |
|          |                                     |                | org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk15to18:1.85,                       |
|          |                                     |                | https://github.com/bcgit/bc-java.git - r1rv85                                                        |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | bcprov-jdk18on-1.84.jar             | CVE-2026-58059 | Upgrade to version org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bcprov-lts8on:2.73.12,          |
|          |                                     |                | org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bc-fips:2.0.2,  |
|          |                                     |                | org.bouncycastle:bcprov-jdk15to18:1.85, https://github.com/bcgit/bc-java.git - r1rv85                |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | bcprov-jdk18on-1.84.jar             | CVE-2026-58060 | Upgrade to version org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,      |
|          |                                     |                | org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bc-fips:2.0.2 |
|          |                                     |                | , https://github.com/bcgit/bc-java.git - r1rv85                                                      |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | bcprov-jdk18on-1.84.jar             | CVE-2026-58061 | Upgrade to version org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcprov-jdk18on:1.85,              |
|          |                                     |                | org.bouncycastle:bc-fips:2.0.2,org.bouncycastle:bcprov-lts8on:2.73.12,                               |
|          |                                     |                | org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bc-fips:1.0.2.7,                             |
|          |                                     |                | https://github.com/bcgit/bc-java.git - r1rv85                                                        |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | bcutil-jdk18on-1.84.jar             | CVE-2026-59645 | Upgrade to version org.bouncycastle:bcutil-lts8on:2.73.12,org.bouncycastle:bcutil-fips:2.1.7,        |
|          |                                     |                | org.bouncycastle:bcutil-jdk18on:1.85,org.bouncycastle:bcutil-jdk15to18:1.85,                         |
|          |                                     |                | org.bouncycastle:bcutil-fips:2.0.7, https://github.com/bcgit/bc-java.git - r1rv85                    |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | netty-handler-4.1.136.Final.jar     | CVE-2026-62243 | Upgrade to version io.netty:netty-handler:4.1.137.Final,io.netty:netty-handler:4.2.17.Final          |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | netty-handler-4.1.136.Final.jar     | CVE-2026-75596 | Upgrade to version io.netty:netty-handler:4.2.17.Final,io.netty:netty-handler:4.1.137.Final,         |
|          |                                     |                | https://github.com/netty/netty.git - netty-4.2.17.Final, https://github.com/netty/netty.git -        |
|          |                                     |                | netty-4.1.137.Final                                                                                  |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | bcpkix-jdk18on-1.84.jar             | CVE-2026-13586 | Upgrade to version org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bc-fips:2.0.2,            |
|          |                                     |                | org.bouncycastle:bcpkix-jdk15to18:1.85,org.bouncycastle:bcpkix-lts8on:2.73.12,                       |
|          |                                     |                | org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcpkix-jdk18on:1.85 |
|          |                                     |                | ,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,                        |
|          |                                     |                | https://github.com/bcgit/bc-java.git - r1rv85                                                        |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | bcpkix-jdk18on-1.84.jar             | CVE-2026-15055 | Upgrade to version org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcpkix-fips:2.1.12,       |
|          |                                     |                | org.bouncycastle:bcpkix-fips:1.0.12,org.bouncycastle:bcprov-jdk18on:1.85,                            |
|          |                                     |                | org.bouncycastle:bcpkix-lts8on:2.73.12,org.bouncycastle:bcpkix-jdk15to18:1.85,                       |
|          |                                     |                | org.bouncycastle:bcpkix-fips:2.0.12,org.bouncycastle:bcpkix-jdk18on:1.85,                            |
|          |                                     |                | org.bouncycastle:bcprov-jdk15to18:1.85, https://github.com/bcgit/bc-java.git - r1rv85                |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | bcpkix-jdk18on-1.84.jar             | CVE-2026-59647 | Upgrade to version org.bouncycastle:bcpkix-lts8on:2.73.12,org.bouncycastle:bcpkix-jdk18on:1.85,      |
|          |                                     |                | org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcpkix-fips:2.0.12,                            |
|          |                                     |                | org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcpkix-fips:2.1.12,                          |
|          |                                     |                | org.bouncycastle:bcpkix-fips:1.0.12,org.bouncycastle:bcpkix-jdk15to18:1.85,                          |
|          |                                     |                | org.bouncycastle:bcprov-jdk15to18:1.85, https://github.com/bcgit/bc-java.git - r1rv85                |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | bcprov-jdk18on-1.84.jar             | CVE-2026-12185 | Upgrade to version org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcprov-jdk18on:1.85,      |
|          |                                     |                | org.bouncycastle:bcprov-jdk15to18:1.85, https://github.com/bcgit/bc-java.git - r1rv85                |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | bcprov-jdk18on-1.84.jar             | CVE-2026-13586 | Upgrade to version org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bc-fips:2.0.2,            |
|          |                                     |                | org.bouncycastle:bcpkix-jdk15to18:1.85,org.bouncycastle:bcpkix-lts8on:2.73.12,                       |
|          |                                     |                | org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bc-fips:2.1.3,org.bouncycastle:bcpkix-jdk18on:1.85 |
|          |                                     |                | ,org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,                        |
|          |                                     |                | https://github.com/bcgit/bc-java.git - r1rv85                                                        |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | bcprov-jdk18on-1.84.jar             | CVE-2026-15055 | Upgrade to version org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcpkix-fips:2.1.12,       |
|          |                                     |                | org.bouncycastle:bcpkix-fips:1.0.12,org.bouncycastle:bcprov-jdk18on:1.85,                            |
|          |                                     |                | org.bouncycastle:bcpkix-lts8on:2.73.12,org.bouncycastle:bcpkix-jdk15to18:1.85,                       |
|          |                                     |                | org.bouncycastle:bcpkix-fips:2.0.12,org.bouncycastle:bcpkix-jdk18on:1.85,                            |
|          |                                     |                | org.bouncycastle:bcprov-jdk15to18:1.85, https://github.com/bcgit/bc-java.git - r1rv85                |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | bcprov-jdk18on-1.84.jar             | CVE-2026-58063 | Upgrade to version org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bc-fips:2.0.2,              |
|          |                                     |                | org.bouncycastle:bc-fips:1.0.2.7,org.bouncycastle:bcprov-lts8on:2.73.12,                             |
|          |                                     |                | org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bc-fips:2.1.3,                               |
|          |                                     |                | https://github.com/bcgit/bc-java.git - r1rv85                                                        |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | bcprov-jdk18on-1.84.jar             | CVE-2026-59647 | Upgrade to version org.bouncycastle:bcpkix-lts8on:2.73.12,org.bouncycastle:bcpkix-jdk18on:1.85,      |
|          |                                     |                | org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcpkix-fips:2.0.12,                            |
|          |                                     |                | org.bouncycastle:bcprov-lts8on:2.73.12,org.bouncycastle:bcpkix-fips:2.1.12,                          |
|          |                                     |                | org.bouncycastle:bcpkix-fips:1.0.12,org.bouncycastle:bcpkix-jdk15to18:1.85,                          |
|          |                                     |                | org.bouncycastle:bcprov-jdk15to18:1.85, https://github.com/bcgit/bc-java.git - r1rv85                |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | bcprov-jdk18on-1.84.jar             | CVE-2026-59648 | Upgrade to version org.bouncycastle:bcpg-fips:1.0.13,org.bouncycastle:bcpg-jdk18on:1.85,             |
|          |                                     |                | org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,                         |
|          |                                     |                | org.bouncycastle:bcpg-jdk15to18:1.85,org.bouncycastle:bcpg-fips:2.0.13,                              |
|          |                                     |                | org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcpg-lts8on:2.73.12,                         |
|          |                                     |                | org.bouncycastle:bcpg-fips:2.1.13, https://github.com/bcgit/bc-java.git - r1rv85                     |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | bcprov-jdk18on-1.84.jar             | CVE-2026-59651 | Upgrade to version org.bouncycastle:bcprov-jdk18on:1.85,org.bouncycastle:bcprov-lts8on:2.73.12,      |
|          |                                     |                | org.bouncycastle:bcprov-jdk15to18:1.85, https://github.com/bcgit/bc-java.git - r1rv85                |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | bcprov-jdk18on-1.84.jar             | CVE-2026-59652 | Upgrade to version org.bouncycastle:bcprov-jdk15to18:1.85,org.bouncycastle:bcprov-jdk18on:1.85,      |
|          |                                     |                | https://github.com/bcgit/bc-java.git - r1rv85                                                        |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | jackson-databind-2.22.0.jar         | CVE-2026-19032 | Upgrade to version tools.jackson.core:jackson-databind:3.2.2,                                        |
|          |                                     |                | com.fasterxml.jackson.core:jackson-databind:2.22.2,                                                  |
|          |                                     |                | com.fasterxml.jackson.core:jackson-databind:2.21.6,tools.jackson.core:jackson-databind:3.1.6,        |
|          |                                     |                | com.fasterxml.jackson.core:jackson-databind:2.18.10                                                  |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | jackson-databind-2.22.0.jar         | CVE-2026-54515 | Upgrade to version  https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4,      |
|          |                                     |                | com.fasterxml.jackson.core:jackson-databind:2.21.5,                                                  |
|          |                                     |                | com.fasterxml.jackson.core:jackson-databind:2.22.1,                                                  |
|          |                                     |                | https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.18.9,                         |
|          |                                     |                | https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.21.5,                         |
|          |                                     |                | https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.22.1                          |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | jackson-databind-2.22.0.jar         | CVE-2026-59889 | Upgrade to version com.fasterxml.jackson.core:jackson-databind:2.21.5,                               |
|          |                                     |                | tools.jackson.core:jackson-databind:3.1.5,tools.jackson.core:jackson-databind:3.2.1,                 |
|          |                                     |                | com.fasterxml.jackson.core:jackson-databind:2.22.1                                                   |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | jackson-databind-2.22.0.jar         | CVE-2026-77310 | Upgrade to version tools.jackson.core:jackson-databind:3.2.1,                                        |
|          |                                     |                | com.fasterxml.jackson.core:jackson-databind:2.18.9,                                                  |
|          |                                     |                | com.fasterxml.jackson.core:jackson-databind:2.21.5,                                                  |
|          |                                     |                | com.fasterxml.jackson.core:jackson-databind:2.22.1,tools.jackson.core:jackson-databind:3.1.5         |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | jackson-databind-2.22.0.jar         | CVE-2026-83557 | Upgrade to version tools.jackson.core:jackson-databind:3.1.6,                                        |
|          |                                     |                | com.fasterxml.jackson.core:jackson-databind:2.22.2,                                                  |
|          |                                     |                | com.fasterxml.jackson.core:jackson-databind:2.18.10,                                                 |
|          |                                     |                | com.fasterxml.jackson.core:jackson-databind:2.21.6,tools.jackson.core:jackson-databind:3.2.2         |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | micrometer-core-1.17.0.jar          | CVE-2026-59295 | Upgrade to version io.micrometer:micrometer-core:1.17.1,io.micrometer:micrometer-core:1.16.7         |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | micrometer-core-1.17.0.jar          | CVE-2026-59296 | Upgrade to version io.micrometer:micrometer-registry-statsd:1.16.7,                                  |
|          |                                     |                | io.micrometer:micrometer-registry-statsd:1.17.1,                                                     |
|          |                                     |                | https://github.com/micrometer-metrics/micrometer.git - v1.16.7,io.micrometer:micrometer-core:1.17.1, |
|          |                                     |                | io.micrometer:micrometer-core:1.16.7, https://github.com/micrometer-metrics/micrometer.git - v1.17.1 |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | netty-codec-http-4.1.136.Final.jar  | CVE-2026-59903 | Upgrade to version  https://github.com/netty/netty.git - netty-4.1.137.Final,                        |
|          |                                     |                | https://github.com/netty/netty.git - netty-4.2.17.Final                                              |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | netty-codec-socks-4.1.136.Final.jar | CVE-2026-62380 | Upgrade to version io.netty:netty-codec-socks:4.2.17.Final,io.netty:netty-codec-socks:4.1.137.Final  |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+
| MEDIUM   | okio-2.10.0.jar                     | CVE-2023-3635  | Upgrade to version com.squareup.okio:okio-jvm:3.4.0                                                  |
+----------+-------------------------------------+----------------+------------------------------------------------------------------------------------------------------+


Paths at risk

P = policy violation
MSC = malicious vulnerability
CRITICAL/HIGH/MEDIUM/LOW = vulnerability severity

okhttp-4.12.0.jar
|-- okio-2.10.0.jar [1 MEDIUM]
okio-2.10.0.jar [1 MEDIUM]
micrometer-registry-prometheus-1.17.0.jar
|-- micrometer-core-1.17.0.jar [2 MEDIUM]
quarkus-jackson-3.38.1.jar
|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- jackson-datatype-jdk8-2.22.0.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- jackson-datatype-jsr310-2.22.0.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- jackson-module-parameter-names-2.22.0.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- vertx-core-4.5.30.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
	|-- netty-codec-http-4.1.136.Final.jar [1 MEDIUM]
		|-- netty-handler-4.1.136.Final.jar [1 CRITICAL, 2 HIGH]
	|-- netty-handler-proxy-4.1.136.Final.jar
		|-- netty-codec-http-4.1.136.Final.jar [1 MEDIUM]
		|-- netty-codec-socks-4.1.136.Final.jar [1 MEDIUM]
		|-- netty-handler-4.1.136.Final.jar [1 CRITICAL, 2 HIGH]
	|-- netty-handler-4.1.136.Final.jar [1 CRITICAL, 2 HIGH]
	|-- netty-resolver-dns-4.1.136.Final.jar
		|-- netty-handler-4.1.136.Final.jar [1 CRITICAL, 2 HIGH]
quarkus-oidc-client-3.38.1.jar
|-- quarkus-oidc-common-3.38.1.jar
	|-- smallrye-mutiny-vertx-web-client-3.23.0.jar
		|-- jackson-databind-2.22.0.jar [5 MEDIUM]
		|-- vertx-web-client-4.5.30.jar
			|-- jackson-databind-2.22.0.jar [5 MEDIUM]
quarkus-rest-client-jackson-3.38.1.jar
|-- resteasy-reactive-jackson-3.38.1.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
quarkus-rest-client-3.38.1.jar
|-- quarkus-tls-registry-3.38.1.jar
	|-- smallrye-private-key-pem-parser-0.9.3.jar
		|-- bcpkix-jdk18on-1.84.jar [3 HIGH, 3 MEDIUM]
		|-- bcprov-jdk18on-1.84.jar [3 CRITICAL, 8 HIGH, 8 MEDIUM]
	|-- vertx-web-4.5.30.jar
		|-- jackson-databind-2.22.0.jar [5 MEDIUM]
quarkus-smallrye-fault-tolerance-3.38.1.jar
|-- smallrye-fault-tolerance-6.11.2.jar
	|-- micrometer-core-1.17.0.jar [2 MEDIUM]
quarkus-smallrye-health-3.38.1.jar
|-- quarkus-vertx-http-3.38.1.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
quarkus-vertx-3.38.1.jar
|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- quarkus-netty-3.38.1.jar
	|-- netty-codec-http2-4.1.136.Final.jar
		|-- netty-codec-http-4.1.136.Final.jar [1 MEDIUM]
		|-- netty-handler-4.1.136.Final.jar [1 CRITICAL, 2 HIGH]
	|-- netty-codec-http-4.1.136.Final.jar [1 MEDIUM]
	|-- netty-handler-4.1.136.Final.jar [1 CRITICAL, 2 HIGH]
|-- smallrye-mutiny-vertx-core-3.23.0.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- smallrye-fault-tolerance-vertx-6.11.2.jar
	|-- smallrye-fault-tolerance-core-6.11.2.jar
		|-- micrometer-core-1.17.0.jar [2 MEDIUM]
bcpkix-jdk18on-1.84.jar [3 HIGH, 3 MEDIUM]
|-- bcutil-jdk18on-1.84.jar [1 HIGH]
	|-- bcprov-jdk18on-1.84.jar [3 CRITICAL, 8 HIGH, 8 MEDIUM]
indy-model-core-java-2.2.jar
|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- atlas-bindings-jackson-identities-1.1.9.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- atlas-relationships-api-1.1.9.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
artifactory-java-client-services-2.21.3-SNAPSHOT.jar
|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- artifactory-java-client-api-2.21.3-SNAPSHOT.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- artifactory-java-client-httpClient-2.21.3-SNAPSHOT.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- build-info-api-2.43.9.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- file-specs-java-1.1.2.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]


No Policy violations were detected

Project 'generic-http-proxy' was updated, for more information, visit the Mend platform: https://ibmets.whitesourcesoftware.com/app/orgs/Enterprise%20Applications/applications/summary?project=b23fdc1f-fcf6-4ed7-8271-046e6a82d10f
Or the Core UI: https://ibmets.whitesourcesoftware.com/Wss/WSS.html#!project;token=57b3852ebb35456f89dc27c38b7c51197136192ff5c84c3ab56b8bdd74d2f5cb

Mend AI scan succeeded.

Support Token: 0add32391a5614cc3ab10a56be906cabd1788340190350
SAST scan output
*no findings*

Full logs and artifacts

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants