Skip to content

Set logback-classic scope to test - #138

Merged
rnc merged 1 commit into
Commonjava:masterfrom
dwalluck:fix-logback-classic-scope
Oct 9, 2026
Merged

rnc merged 1 commit into
Commonjava:masterfrom
dwalluck:fix-logback-classic-scope

Conversation

@dwalluck

@dwalluck dwalluck commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

This was a compile dependency, caught on project-ncl/build-finder#1797. It's only needed for tests.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Mend Scan Results

Status: ⚠️ Findings detected

⚠️ SCA findings detected

SCA scan output



Identified 12 dependencies

Detected 4 vulnerabilities (0 Critical, 4 High, 0 Medium, 0 Low)

+----------+-----------------------------+----------------+------------------------------------------------------------------------------------------------------+
| SEVERITY |           LIBRARY           |       ID       |                                               TOP FIX                                                |
+----------+-----------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | jackson-core-2.22.2.jar     | CVE-2026-89407 | Upgrade to version com.fasterxml.jackson.core:jackson-core:2.21.7,                                   |
|          |                             |                | com.fasterxml.jackson.core:jackson-core:2.18.11, https://github.com/FasterXML/jackson-core.git -     |
|          |                             |                | jackson-core-2.21.7, https://github.com/FasterXML/jackson-core.git - jackson-core-3.1.7,             |
|          |                             |                | https://github.com/FasterXML/jackson-core.git - jackson-core-2.18.11,                                |
|          |                             |                | https://github.com/FasterXML/jackson-core.git - jackson-core-3.2.2,                                  |
|          |                             |                | https://github.com/FasterXML/jackson-core.git - jackson-core-2.22.3,                                 |
|          |                             |                | tools.jackson.core:jackson-core:3.2.2,tools.jackson.core:jackson-core:3.1.7,                         |
|          |                             |                | com.fasterxml.jackson.core:jackson-core:2.22.3                                                       |
+----------+-----------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | jackson-core-2.22.2.jar     | CVE-2026-89425 | Upgrade to version  https://github.com/FasterXML/jackson-core.git - jackson-core-3.2.3,              |
|          |                             |                | https://github.com/FasterXML/jackson-core.git - jackson-core-2.22.3,                                 |
|          |                             |                | https://github.com/FasterXML/jackson-core.git - jackson-core-2.21.7,                                 |
|          |                             |                | https://github.com/FasterXML/jackson-core.git - jackson-core-2.18.11,                                |
|          |                             |                | https://github.com/FasterXML/jackson-core.git - jackson-core-3.1.7,                                  |
|          |                             |                | tools.jackson.core:jackson-core:3.1.7,com.fasterxml.jackson.core:jackson-core:2.22.3,                |
|          |                             |                | com.fasterxml.jackson.core:jackson-core:2.21.7,com.fasterxml.jackson.core:jackson-core:2.18.11,      |
|          |                             |                | tools.jackson.core:jackson-core:3.2.3                                                                |
+----------+-----------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | jackson-databind-2.22.2.jar | CVE-2026-91776 | Upgrade to version  https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.7,      |
|          |                             |                | https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.2.3,                          |
|          |                             |                | https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.21.7,                         |
|          |                             |                | https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.22.3,                         |
|          |                             |                | tools.jackson.core:jackson-databind:3.2.3,tools.jackson.core:jackson-databind:3.1.7,                 |
|          |                             |                | com.fasterxml.jackson.core:jackson-databind:2.22.3,                                                  |
|          |                             |                | com.fasterxml.jackson.core:jackson-databind:2.21.7,                                                  |
|          |                             |                | com.fasterxml.jackson.core:jackson-databind:2.18.11,                                                 |
|          |                             |                | https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.18.11                         |
+----------+-----------------------------+----------------+------------------------------------------------------------------------------------------------------+
| HIGH     | jackson-databind-2.22.2.jar | CVE-2026-91777 | Upgrade to version tools.jackson.core:jackson-databind:3.1.7,                                        |
|          |                             |                | tools.jackson.core:jackson-databind:3.2.3, https://github.com/FasterXML/jackson-databind.git -       |
|          |                             |                | jackson-databind-2.21.7, https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.2.3, |
|          |                             |                | https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.22.3,                         |
|          |                             |                | https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.18.11,                        |
|          |                             |                | https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.7,                          |
|          |                             |                | com.fasterxml.jackson.core:jackson-databind:2.22.3,                                                  |
|          |                             |                | com.fasterxml.jackson.core:jackson-databind:2.21.7,                                                  |
|          |                             |                | com.fasterxml.jackson.core:jackson-databind:2.18.11                                                  |
+----------+-----------------------------+----------------+------------------------------------------------------------------------------------------------------+


Paths at risk

P = policy violation
MSC = malicious vulnerability
CRITICAL/HIGH/MEDIUM/LOW = vulnerability severity

atlas-bindings-parent-1.2.4-SNAPSHOT.pom
|-- atlas-bindings-jackson-identities-1.2.4-SNAPSHOT.jar
	|-- jackson-core-2.22.2.jar [2 HIGH]
	|-- jackson-databind-2.22.2.jar [2 HIGH]
		|-- jackson-core-2.22.2.jar [2 HIGH]
atlas-relationships-api-1.2.4-SNAPSHOT.jar
|-- jackson-core-2.22.2.jar [2 HIGH]
|-- jackson-databind-2.22.2.jar [2 HIGH]
	|-- jackson-core-2.22.2.jar [2 HIGH]
|-- atlas-bindings-jackson-identities-1.2.4-SNAPSHOT.jar
	|-- jackson-core-2.22.2.jar [2 HIGH]
	|-- jackson-databind-2.22.2.jar [2 HIGH]


No Policy violations were detected

Project 'atlas-pr' was updated, for more information, visit the Mend platform: https://ibmets.whitesourcesoftware.com/app/orgs/Enterprise%20Applications/applications/summary?project=b9e17d8a-216c-445c-98b6-7798f70870d9
Or the Core UI: https://ibmets.whitesourcesoftware.com/Wss/WSS.html#!project;token=9569e9d7a0404c70bfeee3f107a389e606d7e27d43eb4f18b9fc154da6fe5ab5

Mend AI scan succeeded.

Support Token: 2152d969f2c4948b2a1a08f1d424ec29e1791399973496
SAST scan output
*no findings*

Full logs and artifacts

@dwalluck
dwalluck requested review from patrikk0123 and rnc October 7, 2026 19:08
@rnc
rnc merged commit c473639 into Commonjava:master Oct 9, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants