Skip to content

bump logback to 1.5.16 (#1003)

0d05e04
Select commit
Loading
Failed to load commit list.
Open

[Backport 2.x] bump logback to 1.5.16 #1004

bump logback to 1.5.16 (#1003)
0d05e04
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Security Check failed Feb 26, 2025 in 5m 59s

Security Report

4 new vulnerabilities were introduced in this branch.

❌ New vulnerabilities:

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
WS-2022-0468

Path to dependency file: /core-spi/build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.11.4/593f7b18bab07a76767f181e2a2336135ce82cc4/jackson-core-2.11.4.jar

Dependency Hierarchy:

-> framework-2.20.0-SNAPSHOT.jar (Root Library)

   -> opensearch-rest-client-sniffer-2.20.0-SNAPSHOT.jar

     -> ❌ jackson-core-2.11.4.jar (Vulnerable Library)

High 7.5 jackson-core-2.11.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-core:2.15.0 None
WS-2022-0468

Path to dependency file: /core-spi/build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.11.4/593f7b18bab07a76767f181e2a2336135ce82cc4/jackson-core-2.11.4.jar

Dependency Hierarchy:

-> opensearch-2.20.0-SNAPSHOT.jar (Root Library)

   -> opensearch-core-2.20.0-SNAPSHOT.jar

     -> ❌ jackson-core-2.11.4.jar (Vulnerable Library)

High 7.5 jackson-core-2.11.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-core:2.15.0 None
WS-2021-0616

Path to dependency file: /core-spi/build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.11.4/593f7b18bab07a76767f181e2a2336135ce82cc4/jackson-core-2.11.4.jar

Dependency Hierarchy:

-> framework-2.20.0-SNAPSHOT.jar (Root Library)

   -> opensearch-rest-client-sniffer-2.20.0-SNAPSHOT.jar

     -> ❌ jackson-core-2.11.4.jar (Vulnerable Library)

Medium 5.9 jackson-core-2.11.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.12.6, 2.13.1; com.fasterxml.jackson.core:jackson-core:2.12.6, 2.13.1 None
WS-2021-0616

Path to dependency file: /core-spi/build.gradle

Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/com.fasterxml.jackson.core/jackson-core/2.11.4/593f7b18bab07a76767f181e2a2336135ce82cc4/jackson-core-2.11.4.jar

Dependency Hierarchy:

-> opensearch-2.20.0-SNAPSHOT.jar (Root Library)

   -> opensearch-core-2.20.0-SNAPSHOT.jar

     -> ❌ jackson-core-2.11.4.jar (Vulnerable Library)

Medium 5.9 jackson-core-2.11.4.jar Upgrade to version: com.fasterxml.jackson.core:jackson-databind:2.12.6, 2.13.1; com.fasterxml.jackson.core:jackson-core:2.12.6, 2.13.1 None

Base branch total remaining vulnerabilities: 0
Base branch commit: 61c9b3bc4ed1129f392bf0625a0cc8f9228d3412


Total libraries scanned: 223

Scan token: 86a8ec33e13843f68c6a950ef4c930c7