Uh oh!
There was an error while loading. Please reload this page.
Update dependency org.eclipse.jetty:jetty-server to v12 - #21
Update dependency org.eclipse.jetty:jetty-server to v12#21dev-mend-for-github-com[bot] wants to merge 1 commit into
Security Report
❗️Scan Warnings: The scan completed with warnings. The integration encountered issues with one or more projects in this repository. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.
Scan Details Report
maven
/tmp/ws-scm/OpenRefine/pom.xml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | [ERROR] Failed to execute goal on project core: Could not resolve dependencies for project org.openrefine:core:jar:3.10-SNAPSHOT |
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
CVE-941441-362681Path to dependency file: /main/tests/cypress/package.json Path to vulnerable library: /main/tests/cypress/package.json Dependency Hierarchy: -> cypress-14.2.0.tgz (Root Library) -> execa-4.1.0.tgz -> get-stream-5.2.0.tgz -> pump-3.0.0.tgz -> ❌ once-1.4.0.tgz (Vulnerable Library) | 9.8 | Transitive once-1.4.0.tgz | cypress-14.2.0.tgz | None | |||
CVE-2025-49146Path to dependency file: /extensions/database/pom.xml Path to vulnerable library: /extensions/database/pom.xml Dependency Hierarchy: -> ❌ postgresql-42.7.5.jar (Vulnerable Library) | 8.2 | Direct postgresql-42.7.5.jar | postgresql-42.7.5.jar | 42.7.7 | None | ||
CVE-2026-42198Path to dependency file: /extensions/database/pom.xml Path to vulnerable library: /extensions/database/pom.xml Dependency Hierarchy: -> ❌ postgresql-42.7.5.jar (Vulnerable Library) | 7.5 | Direct postgresql-42.7.5.jar | postgresql-42.7.5.jar | 42.7.11 | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2026-59888 | jackson-databind-2.18.3.jar |
| CVE-2024-7708 | jetty-server-10.0.16.jar |
| CVE-2025-48924 | commons-lang3-3.17.0.jar |
| CVE-2024-9823 | jetty-servlets-10.0.16.jar |
| CVE-2026-2332 | jetty-http-10.0.16.jar |
| CVE-2024-7254 | protobuf-java-3.24.3.jar |
| CVE-2024-6763 | jetty-http-10.0.16.jar |
| CVE-2026-6790 | jetty-server-10.0.16.jar |
| CVE-89165-157983 | jaxb-api-2.3.1.jar |
| CVE-2026-54515 | jackson-databind-2.18.3.jar |
| CVE-2025-48924 | commons-lang-2.6.jar |
| CVE-2026-54512 | jackson-databind-2.18.3.jar |
| CVE-2020-13936 | velocity-1.6.3.jar |
| CVE-2026-59889 | jackson-databind-2.18.3.jar |
| CVE-2025-48734 | commons-beanutils-1.9.4.jar |
| CVE-2026-54514 | jackson-databind-2.18.3.jar |
| GHSA-257q-pv89-v3xv | jquery-1.11.1.min.js |
| CVE-2026-43869 | libthrift-0.19.0.jar |
| CVE-842749-413332 | commons-lang-2.6.jar |
Base branch total remaining vulnerabilities: 52
Base branch commit: 085fd97a71ea22eacc085e437f7fdbe3a577362c
Total libraries scanned: 208
Scan token: 77b9f51c12c943378737f4a5458537f2