Sitelet https://github.com/dapr/java-sdk/pull/1821
Skip to content

fix: Upgrade dependencies with known CVEs - #1821

Open
javier-aliaga wants to merge 1 commit into
dapr:masterfrom
javier-aliaga:fix/1.19-cves
Open

javier-aliaga wants to merge 1 commit into
dapr:masterfrom
javier-aliaga:fix/1.19-cves

Conversation

@javier-aliaga

Copy link
Copy Markdown
Contributor

Description

Clears every known vulnerability in the resolved runtime dependencies before cutting 1.19.0-rc-0. MvnRepository flags five jackson-databind CVEs on dapr-sdk 1.18.1 (CVE-2026-91777, -91776, -83557, -68497, -19032); master was on Jackson 2.21.2 and affected as well.

Dependency Before After Fixes
Jackson 2 (jackson.version, root + sdk-bom) 2.21.2 2.21.7 16 advisories in jackson-databind/core, incl. the 5 above
Jackson 3 (tools.jackson:jackson-bom) 3.1.0 / 3.1.1 3.1.7 15 advisories in jackson-databind/core
Netty (netty.version, root + sdk-bom) 4.2.16.Final 4.2.17.Final netty-handler, netty-codec-http
Spring Boot (springboot.version, springboot4.version) 4.0.5 4.0.8 spring-boot, Spring Framework 7.0.9, Spring Data 2025.1.7, logback, log4j-api
OpenTelemetry (opentelemetry.version) 1.55.0 (resolved) 1.62.0 opentelemetry-api
Tomcat (tomcat-embed-core, examples only) 11.0.20 11.0.25 Spring Boot 4.0.8 still manages 11.0.24

The OpenTelemetry and Jackson 3 BOMs now come before spring-boot-dependencies in the root pom; before, Spring Boot's managed versions won. The modules that import the Spring Boot 4 BOM locally (dapr-spring-boot-autoconfigure, -starter, -starter-test, dapr-spring-data, sdk-tests, spring-boot-examples, spring-boot-sdk-tests) also import the Jackson 2 and OpenTelemetry BOMs before it, for the same reason.

Verified with an OSV scan of mvn dependency:list (runtime scope) across all 38 modules including the integration-tests profile: 20 vulnerable artifacts before, 0 after.

Issue reference

N/A (pre-release CVE sweep).

Checklist

  • Code compiles correctly
  • Created/updated tests
  • Extended the documentation

Jackson 2.21.7, Jackson 3 3.1.7, Netty 4.2.17.Final, Spring Boot 4.0.8,
OpenTelemetry 1.62.0 and Tomcat 11.0.25. The OpenTelemetry and Jackson
BOMs are imported before the Spring Boot BOM, including in the modules
that import the Spring Boot 4 BOM locally, so they are not overridden.

Signed-off-by: Javier Aliaga <javier@diagrid.io>
@javier-aliaga
javier-aliaga requested review from a team as code owners October 2, 2026 10:12
Copilot AI balanced review requested due to automatic review settings October 2, 2026 10:12

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The published SDK BOM does not propagate the OpenTelemetry security constraint to consumers.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Upgrades runtime dependencies to patched versions and adjusts BOM precedence to avoid vulnerable Spring Boot-managed versions.

Changes:

  • Updates Jackson, Netty, Spring Boot, OpenTelemetry, and Tomcat.
  • Prioritizes security-patched BOMs over Spring Boot dependency management.
  • Aligns Spring Boot 4 modules with updated dependency versions.
File Description
pom.xml Updates root dependency versions and BOM ordering.
sdk-bom/​pom.xml Updates exported Jackson and Netty constraints.
sdk-tests/​pom.xml Aligns test dependency management.
spring-boot-sdk-tests/​pom.xml Updates Spring Boot and security BOMs.
spring-boot-examples/​pom.xml Updates example dependency management.
dapr-spring/​dapr-spring-data/​pom.xml Aligns Spring Data dependencies.
dapr-spring/​dapr-spring-boot-autoconfigure/​pom.xml Updates autoconfiguration dependency constraints.
dapr-spring/​dapr-spring-boot-starters/​dapr-spring-boot-starter/​pom.xml Updates starter dependency management.
dapr-spring/​dapr-spring-boot-starters/​dapr-spring-boot-starter-test/​pom.xml Updates test starter dependency management.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread sdk-bom/pom.xml
<netty.version>4.2.16.Final</netty.version>
<jackson.version>2.21.2</jackson.version>
<netty.version>4.2.17.Final</netty.version>
<jackson.version>2.21.7</jackson.version>
@codecov

codecov Bot commented Oct 2, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 79.11%. Comparing base (449b720) to head (dd06fce).
⚠️ Report is 1 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff            @@
##             master    #1821   +/-   ##
=========================================
  Coverage     79.11%   79.11%           
  Complexity     2604     2604           
=========================================
  Files           264      264           
  Lines          7785     7785           
  Branches        820      820           
=========================================
  Hits           6159     6159           
  Misses         1266     1266           
  Partials        360      360           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants