Skip to content

MCP-647 Bump Jackson 3 pin to 3.2.3 for open SCA CVEs - #592

Merged
damien-urruty-sonarsource merged 2 commits into
masterfrom
task/dam/MCP-647-bump-jackson-3-pin
Oct 2, 2026
Merged

damien-urruty-sonarsource merged 2 commits into
masterfrom
task/dam/MCP-647-bump-jackson-3-pin

Conversation

@damien-urruty-sonarsource

@damien-urruty-sonarsource damien-urruty-sonarsource commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Bump the Gradle resolution pin for Jackson 3 (tools.jackson*) from 3.1.6 to 3.2.3 to remediate open SCA findings (CVE-2026-89407, CVE-2026-91776, CVE-2026-91777)
  • Widen the pin to all tools.jackson* groups so jackson-dataformat-yaml and the BOM stay aligned
  • Refresh main and IT Gradle lockfiles

@hashicorp-vault-sonar-prod

hashicorp-vault-sonar-prod Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

MCP-647

@damien-urruty-sonarsource
damien-urruty-sonarsource marked this pull request as ready for review October 2, 2026 12:08
@damien-urruty-sonarsource damien-urruty-sonarsource changed the title MCP-647 Bump Jackson 3 pin to 3.1.7 for open SCA CVEs MCP-647 Bump Jackson 3 pin to 3.2.3 for open SCA CVEs Oct 2, 2026
@gitar-bot

gitar-bot Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Code Review ✅ Approved

🟡 Medium risk · The Jackson 3 upgrade changes dependency resolution across main and integration builds.

Bumps Jackson 3 pin to 3.1.7 and widens it to cover all tools.jackson* groups to remediate open SCA CVEs (CVE-2026-89407, CVE-2026-91776, CVE-2026-91777). Gradle lockfiles refreshed. No issues found.

Review coverage

🧪 Functional validation 1 of 1 objectives covered

📋 Rules No rules evaluated

🤖 Auto-approval Not enabled · Set up

Implementation Status ✅ 1 of 1 objectives covered
✅ MCP-647 - 1 of 1 objectives covered

This PR covers bumping the Jackson version pin to 3.2.3 to address open SCA CVEs.

✅ 1 covered here
  • ✅ Bump Jackson 3 pin to 3.2.3 for open SCA CVEs
Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Gitar

@sonarqubecloud

sonarqubecloud Bot commented Oct 2, 2026

Copy link
Copy Markdown

@damien-urruty-sonarsource
damien-urruty-sonarsource merged commit 50ff95d into master Oct 2, 2026
12 checks passed
@damien-urruty-sonarsource
damien-urruty-sonarsource deleted the task/dam/MCP-647-bump-jackson-3-pin branch October 2, 2026 13:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants