Skip to content

Update dependency org.eclipse.jetty:jetty-server to v12 - #21

Open
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/major-jetty.version
Open

Update dependency org.eclipse.jetty:jetty-server to v12#21
dev-mend-for-github-com[bot] wants to merge 1 commit into
masterfrom
whitesource-remediate/major-jetty.version

Update dependency org.eclipse.jetty:jetty-server to v12

ab3e0b3
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Aug 13, 2026 in 13m 4s

Security Report

❗️Scan Warnings: The scan completed with warnings. The integration encountered issues with one or more projects in this repository. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.

Scan Details Report

maven

/tmp/ws-scm/OpenRefine/pom.xml

StepLevelDescriptionDetails
Preparing the project for scan⚠WarnOne or more of the installations failed[ERROR] Failed to execute goal on project core: Could not resolve dependencies for project org.openrefine:core:jar:3.10-SNAPSHOT
Resolving the project⚠WarnSome problems occurred while performing the resolution operation
  • Maven failed to detect the POM for the following dependencies:
    [org.eclipse.jetty:jetty-servlets:jar:12.0.35, org.eclipse.jetty:jetty-servlet:jar:12.0.35, org.eclipse.jetty:jetty-webapp:jar:12.0.35]
  • Fallback is used, returns direct dependencies only

You have successfully remediated 19 vulnerabilities, but introduced 3 new vulnerabilities in this branch.

❌ New vulnerabilities:
VulnerabilitySeverity CVSS ScoreVulnerable LibraryDirect LibrarySuggested FixIssueReachability
CVE-941441-362681

Path to dependency file: /main/tests/cypress/package.json

Path to vulnerable library: /main/tests/cypress/package.json

Dependency Hierarchy:

-> cypress-14.2.0.tgz (Root Library)

-> execa-4.1.0.tgz

-> get-stream-5.2.0.tgz

-> pump-3.0.0.tgz

-> ❌ once-1.4.0.tgz (Vulnerable Library)

Critical9.8Transitive once-1.4.0.tgzcypress-14.2.0.tgzNone
CVE-2025-49146

Path to dependency file: /extensions/database/pom.xml

Path to vulnerable library: /extensions/database/pom.xml

Dependency Hierarchy:

-> ❌ postgresql-42.7.5.jar (Vulnerable Library)

High8.2Direct postgresql-42.7.5.jarpostgresql-42.7.5.jar42.7.7None
CVE-2026-42198

Path to dependency file: /extensions/database/pom.xml

Path to vulnerable library: /extensions/database/pom.xml

Dependency Hierarchy:

-> ❌ postgresql-42.7.5.jar (Vulnerable Library)

High7.5Direct postgresql-42.7.5.jarpostgresql-42.7.5.jar42.7.11None

✔️ Remediated vulnerabilities:

VulnerabilityVulnerable Library
CVE-2026-59888jackson-databind-2.18.3.jar
CVE-2024-7708jetty-server-10.0.16.jar
CVE-2025-48924commons-lang3-3.17.0.jar
CVE-2024-9823jetty-servlets-10.0.16.jar
CVE-2026-2332jetty-http-10.0.16.jar
CVE-2024-7254protobuf-java-3.24.3.jar
CVE-2024-6763jetty-http-10.0.16.jar
CVE-2026-6790jetty-server-10.0.16.jar
CVE-89165-157983jaxb-api-2.3.1.jar
CVE-2026-54515jackson-databind-2.18.3.jar
CVE-2025-48924commons-lang-2.6.jar
CVE-2026-54512jackson-databind-2.18.3.jar
CVE-2020-13936velocity-1.6.3.jar
CVE-2026-59889jackson-databind-2.18.3.jar
CVE-2025-48734commons-beanutils-1.9.4.jar
CVE-2026-54514jackson-databind-2.18.3.jar
GHSA-257q-pv89-v3xvjquery-1.11.1.min.js
CVE-2026-43869libthrift-0.19.0.jar
CVE-842749-413332commons-lang-2.6.jar

Base branch total remaining vulnerabilities: 52
Base branch commit: 085fd97a71ea22eacc085e437f7fdbe3a577362c


Total libraries scanned: 208

Scan token: 77b9f51c12c943378737f4a5458537f2