From f58d6aa67c3074f065ac2364184d7e009bc72ce0 Mon Sep 17 00:00:00 2001 From: Ian Ryan <10286358+nextinfinity@users.noreply.github.com> Date: Mon, 28 Sep 2026 22:38:44 -0700 Subject: [PATCH 1/2] Constrain vulnerable transitive libraries and align Jackson modules --- README.md | 17 +++++++++++++++++ build.gradle | 17 +++++++++++++++++ 2 files changed, 34 insertions(+) diff --git a/README.md b/README.md index 66804ca..e7d7c93 100644 --- a/README.md +++ b/README.md @@ -47,6 +47,23 @@ Cipher support solves signature deciphering, **not** YouTube IP blocks, age rest The Docker image includes a healthcheck that polls JDA's Discord connection state, checking that the bot is connected rather than just running. +## Dependency security updates + +`build.gradle` declares a Jackson BOM and security constraints for Commons IO, +jsoup, and Rhino (including its script engine). These override older transitive +versions from Lavaplayer/YouTube without adding unused libraries or forcing +exact versions; newer upstream versions can still win resolution. Dependabot +can track the explicit coordinates instead of relying only on upstream releases. +Keep Jackson modules aligned through the BOM and update Rhino/its engine together. + +After dependency changes, run `./gradlew clean check shadowJar` and inspect +`./gradlew dependencies --configuration runtimeClasspath` (also check +`compileClasspath`, which can resolve differently). Verify the selected version +after any `->`, not just the upstream requested version. Playback should also +be smoke-tested on the deployment host. Alerts refresh after the updated +dependency graph is submitted from the default branch; do not dismiss them +merely because the build passed. + ## Tests Run `./gradlew test` with JDK 25. See [testing guidance](TESTING.md) for scope and conventions. diff --git a/build.gradle b/build.gradle index 571132e..4e841b2 100644 --- a/build.gradle +++ b/build.gradle @@ -56,6 +56,23 @@ dependencies { testImplementation 'org.mockito:mockito-core:5.23.0' mockitoAgent('org.mockito:mockito-core:5.23.0') { transitive = false } + // Align transitive Jackson modules across compile/runtime configurations. + implementation platform('com.fasterxml.jackson:jackson-bom:2.22.3') + constraints { + implementation('commons-io:commons-io:2.22.0') { + because 'Fix GHSA-78wr-2p64-hpwj in Lavaplayer/lava-common transitive dependencies' + } + implementation('org.jsoup:jsoup:1.23.2') { + because 'Fix GHSA-pmhh-3w7g-xqp8 in Lavaplayer transitive dependencies' + } + implementation('org.mozilla:rhino:1.7.15.1') { + because 'Fix GHSA-3w8q-xq97-5j7x without changing the Rhino release line' + } + implementation('org.mozilla:rhino-engine:1.7.15.1') { + because 'Keep the YouTube/Lavaplayer script engine aligned with patched Rhino' + } + } + implementation 'net.dv8tion:JDA:6.7.0' implementation 'club.minnced:jdave-api:0.1.8' runtimeOnly 'club.minnced:jdave-native-linux-x86-64:0.1.8' From 9fe3f2e8234b83758b135535fa34537e5ca9bdec Mon Sep 17 00:00:00 2001 From: Ian Ryan <10286358+nextinfinity@users.noreply.github.com> Date: Mon, 28 Sep 2026 22:46:37 -0700 Subject: [PATCH 2/2] Use explicit Jackson constraints and remove README security guidance --- README.md | 17 ----------------- build.gradle | 8 ++++++-- 2 files changed, 6 insertions(+), 19 deletions(-) diff --git a/README.md b/README.md index e7d7c93..66804ca 100644 --- a/README.md +++ b/README.md @@ -47,23 +47,6 @@ Cipher support solves signature deciphering, **not** YouTube IP blocks, age rest The Docker image includes a healthcheck that polls JDA's Discord connection state, checking that the bot is connected rather than just running. -## Dependency security updates - -`build.gradle` declares a Jackson BOM and security constraints for Commons IO, -jsoup, and Rhino (including its script engine). These override older transitive -versions from Lavaplayer/YouTube without adding unused libraries or forcing -exact versions; newer upstream versions can still win resolution. Dependabot -can track the explicit coordinates instead of relying only on upstream releases. -Keep Jackson modules aligned through the BOM and update Rhino/its engine together. - -After dependency changes, run `./gradlew clean check shadowJar` and inspect -`./gradlew dependencies --configuration runtimeClasspath` (also check -`compileClasspath`, which can resolve differently). Verify the selected version -after any `->`, not just the upstream requested version. Playback should also -be smoke-tested on the deployment host. Alerts refresh after the updated -dependency graph is submitted from the default branch; do not dismiss them -merely because the build passed. - ## Tests Run `./gradlew test` with JDK 25. See [testing guidance](TESTING.md) for scope and conventions. diff --git a/build.gradle b/build.gradle index 4e841b2..ed595f1 100644 --- a/build.gradle +++ b/build.gradle @@ -56,9 +56,13 @@ dependencies { testImplementation 'org.mockito:mockito-core:5.23.0' mockitoAgent('org.mockito:mockito-core:5.23.0') { transitive = false } - // Align transitive Jackson modules across compile/runtime configurations. - implementation platform('com.fasterxml.jackson:jackson-bom:2.22.3') constraints { + implementation('com.fasterxml.jackson.core:jackson-core:2.22.3') { + because 'Fix GHSA-72hv-8253-57qq and GHSA-r7wm-3cxj-wff9 in transitive Jackson versions' + } + implementation('com.fasterxml.jackson.core:jackson-databind:2.22.3') { + because 'Fix reported Jackson databind vulnerabilities, including GHSA-q4xh-88c3-wmh7 and GHSA-gx83-3vf8-gh7j' + } implementation('commons-io:commons-io:2.22.0') { because 'Fix GHSA-78wr-2p64-hpwj in Lavaplayer/lava-common transitive dependencies' }