[Backport 2.0] Update the maven snapshot publish endpoint and credential - #107
Open
opensearch-trigger-bot[bot] wants to merge 1 commit into
Open
[Backport 2.0] Update the maven snapshot publish endpoint and credential#107opensearch-trigger-bot[bot] wants to merge 1 commit into
opensearch-trigger-bot[bot] wants to merge 1 commit into
Mend for GitHub.com / Mend Security Check
failed
Aug 25, 2025 in 4m 17s
Security Report
You have successfully remediated 1 vulnerabilities, but introduced 1 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|
CVE-2025-48924Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/org.apache.commons/commons-lang3/3.12.0/c6842c86792ff03b9f1d1fe2aab8dc23aa6c6f0e/commons-lang3-3.12.0.jar Dependency Hierarchy: -> spotbugs-4.7.3.jar (Root Library) -> ❌ commons-lang3-3.12.0.jar (Vulnerable Library) |
5.3 | commons-lang3-3.12.0.jar | Upgrade to version: org.apache.commons:commons-lang3:3.18.0 | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2025-48924 | commons-lang3-3.14.0.jar |
Base branch total remaining vulnerabilities: 1
Base branch commit: 142be0c20a978d88e9b81c52a0b7a41feee4236a
Total libraries scanned: 66
Scan token: a545bf8ee4284fafad75a264e512a38c
Loading