Resolve vulnerable transitive dependencies and align Jackson - #12
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
becausemessage. No README or application logic changes, exclusions, forced exact versions, or additional test framework.Resolved versions
Commons IO/jsoup originate in Lavaplayer (Commons IO also in lava-common); Rhino comes via Lavaplayer and youtube-source. Lavaplayer 2.2.7 is already the latest published release, so upgrading it alone cannot fix these.
Jackson needs cross-configuration alignment: runtime already selected patched JDA transitive versions, but the submitted dependency graph also contained Lavaplayer's Jackson 2.15.2. The explicit core/databind constraints bring compile and runtime resolution to 2.22.3; Jackson's own transitive metadata selects annotations 2.22. No direct BOM declaration is added. Constraints do not pull in absent modules and allow newer upstream versions to win.
Advisory scope
Addresses the affected versions in currently open alerts #1–#14: Commons IO GHSA-78wr-2p64-hpwj, Rhino GHSA-3w8q-xq97-5j7x, jsoup GHSA-pmhh-3w7g-xqp8, and the reported Jackson core/databind advisories. Checked the advisories' branch-specific ranges, not just the older 2.18.x first-patched versions.
Validation
sh ./gradlew --no-daemon clean check shadowJarpassed (32 tests).compileClasspathandruntimeClasspath; affected modules resolve to the patched versions above.git diff --checkpassed.Live Discord/YouTube playback has not been tested. Smoke-test playback after deploying. GitHub alerts will need a refreshed default-branch dependency submission after merge; this PR does not dismiss alerts or claim a comprehensive vulnerability audit.