Skip to content

Resolve vulnerable transitive dependencies and align Jackson - #12

Merged
nextinfinity merged 2 commits into
mainfrom
fix/transitive-vulnerabilities
Sep 29, 2026
Merged

nextinfinity merged 2 commits into
mainfrom
fix/transitive-vulnerabilities

Conversation

@nextinfinity

@nextinfinity nextinfinity commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Declare Gradle dependency constraints for Jackson core/databind, Commons IO, jsoup, Rhino, and Rhino-engine, with explicit coordinates that dependency-update tooling can track.
  • Keep Rhino on the patched 1.7.15 release line and update the script engine alongside it.
  • Keep motivation in each constraint's because message. No README or application logic changes, exclusions, forced exact versions, or additional test framework.

Resolved versions

Dependency Before (runtime) After
Jackson core/databind 2.22.2 2.22.3
Commons IO 2.13.0 2.22.0
jsoup 1.16.1 1.23.2
Rhino / rhino-engine 1.7.15 1.7.15.1

Commons IO/jsoup originate in Lavaplayer (Commons IO also in lava-common); Rhino comes via Lavaplayer and youtube-source. Lavaplayer 2.2.7 is already the latest published release, so upgrading it alone cannot fix these.

Jackson needs cross-configuration alignment: runtime already selected patched JDA transitive versions, but the submitted dependency graph also contained Lavaplayer's Jackson 2.15.2. The explicit core/databind constraints bring compile and runtime resolution to 2.22.3; Jackson's own transitive metadata selects annotations 2.22. No direct BOM declaration is added. Constraints do not pull in absent modules and allow newer upstream versions to win.

Advisory scope

Addresses the affected versions in currently open alerts #1–#14: Commons IO GHSA-78wr-2p64-hpwj, Rhino GHSA-3w8q-xq97-5j7x, jsoup GHSA-pmhh-3w7g-xqp8, and the reported Jackson core/databind advisories. Checked the advisories' branch-specific ranges, not just the older 2.18.x first-patched versions.

Validation

  • JDK 25: sh ./gradlew --no-daemon clean check shadowJar passed (32 tests).
  • Inspected resolved compileClasspath and runtimeClasspath; affected modules resolve to the patched versions above.
  • Inspected packaged shadow-JAR Maven version metadata for Jackson/Commons IO/jsoup; compared packaged Rhino and Rhino-engine representative classes byte-for-byte against the resolved 1.7.15.1 JARs.
  • git diff --check passed.

Live Discord/YouTube playback has not been tested. Smoke-test playback after deploying. GitHub alerts will need a refreshed default-branch dependency submission after merge; this PR does not dismiss alerts or claim a comprehensive vulnerability audit.

@nextinfinity
nextinfinity merged commit 13a87ee into main Sep 29, 2026
6 of 7 checks passed
@nextinfinity
nextinfinity deleted the fix/transitive-vulnerabilities branch September 29, 2026 05:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant