Skip to content

Conversation

@Mindgamesnl
Copy link

@Mindgamesnl Mindgamesnl commented Sep 26, 2025

Hey there,

This is a small PR to address an issue we encountered recently.
We're trying to update our internal dependencies to address some outdated ones, and would like to upgrade the Jakarta Bind-API to 4.0.*, which is just barely outside the supported range.

I validated that all tests are passing with this change, and do not expect any third-party degradations (but please let me know if I've missed something).

edit: tests are passing when running them through gradle locally on java 17, but seem to be failing in the azure pipelines. Not sure if that's caused by the version bump, or something else is running amok

I'd be happy to contribute further.

(this would also address #3265)

Thanks in advance

@Gen-SIQA-User
Copy link
Collaborator

Checks Summary

Last run: 2025-10-23T14:06:04.665Z

Code Risk Analyzer vulnerability scan found 1 vulnerabilities:

Severity Identifier Package Details Fix
◻Unknown CVE-2025-11226 ch.qos.logback:logback-core
QOS.CH logback-core is vulnerable to Arbitrary Code Execution through file processingGHSA-25qh-j22f-pwp8

ch.qos.logback:logback-core:1.2.13->ch.qos.logback:logback-classic:1.2.13,org.terracotta:server-api:5.12.14,org.terracotta:galvan:5.12.14,org.terracotta.internal:galvan-support:5.12.14,org.terracotta:terracotta-dynamic-config-testing-galvan:5.11.3
1.5.19

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants