Skip to content

chore(deps): bump six libraries with published security fixes - #37626

Merged
wezell merged 4 commits into
mainfrom
issue-36546-safe-dependency-bumps
Sep 22, 2026
Merged

wezell merged 4 commits into
mainfrom
issue-36546-safe-dependency-bumps

Conversation

@wezell

@wezell wezell commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

Why is this one PR?

Because do you know how many cycles of checks and runners and merge queues are needed to get these 6 library bumps in the code base? It would clog up our pipelines for days.... In my mind there is not much danger in pushing these together. Generally I would say one PR per change but we have soooo many and because tests are all passing there is little difference in shipping one at a time vs. shipping them all. Error will be easy to unwind with ai and will take like 5m to realize and revert. (and so long to get merged and released 😄 )

Proposed Changes

Bump six libraries that have published fixes, clearing 9 HIGH/CRITICAL findings from the
container image vulnerability scan. Every bump stays within the same major version and the
same artifact coordinates — no API change, no scope change, no new dependency.

Library From To Clears
tomcat-catalina / -jasper / -jdbc 9.0.120 9.0.122 3 CRITICAL (CVE-2026-65182, CVE-2026-65905, CVE-2026-68525)
org.postgresql:postgresql 42.7.2 42.7.13 CVE-2026-42198
dnsjava:dnsjava 3.5.3 3.6.5 CVE-2024-25638 + 2 x GHSA KeyTrap
core5:httpcore5 (+ httpcore5-h2) 5.3.4 5.4.3 CVE-2026-54399, CVE-2026-54428
com.thoughtworks.xstream:xstream 1.4.20 1.4.21 CVE-2024-47072
io.micrometer:* 1.13.10 1.15.12 CVE-2026-40984

Files: bom/application/pom.xml, parent/pom.xml. Two files, seven lines.

tomcat.version additionally drives the Tomcat distribution zip fetched by the assembly and
every tomcat-* jar, so the 9.0.122 zip and all 9.0.122 artifacts were confirmed present on
Maven Central before the bump. It does not affect a Docker base image: the product image
builds FROM dotcms/java-base (Java 25), and the docker.base.image property that names a
tomcat:* image is unreferenced dead config.

How This Was Verified

  • ./mvnw install -pl :dotcms-core --am -DskipTests -Dmaven.build.cache.enabled=false —
    BUILD SUCCESS, all 12 reactor modules, 6:04.
    The build cache was disabled deliberately so the compile could not be short-circuited.
  • dependency:list confirms all six at the new versions, with no superseded version left
    anywhere
    in the tree — including all 13 tomcat-* artifacts at 9.0.122.

Not verified: runtime behaviour. No tests were run. The realistic risk areas are
micrometer (a minor bump, and it feeds the telemetry system) and Tomcat (it drives the
servlet container). Reviewers may want at least a smoke test on those two.

Checklist

  • Tests
  • Translations — n/a, no user-facing strings
  • Security Implications Contemplated — this PR is remediation; see the table above and the
    exclusions below for the deliberate non-changes

Additional Info

Refs #36546 — deliberately not a closing reference. This PR covers only the subset of that
issue that is fixable by a version bump, and the issue still has open work under PR #36548
(commons-fileupload, grpc). It should stay open.

Deliberately out of scope, with reasons:

Library Why not here
commons-fileupload, io.grpc:grpc-netty-shaded Both need code changes, not just a version change — covered by PR #36548
software.amazon.ion:ion-java 1.0.2 The published fix is at a different groupId (com.amazon.ion); the coordinate in use (software.amazon.ion) stops at 1.5.1, so the scan's "fixed in 1.10.5" is unreachable without a coordinate migration
jackson 2.17.2 Minor bump with a wide blast radius; tracked separately as #32688
graphql-java 17.5 Major version jump
elasticsearch 7.10.2 Deliberate pin, last Apache-2.0 release
org.jdom:jdom 1.1.3 No patched 1.x exists; needs a jdom2 migration with WebDAV risk
cryptacular, xmlsec Ship from the separate dotCMS/com.dotcms.dotsaml repo
tinymce Frontend, tracked separately

Also worth noting for reviewers: netty from the same issue is already fixed on main
(b6a18e74b1), so it is not part of this PR.

The scan that produced this list was run as linux/arm64. The Java and Node layers are
architecture-independent, but the apt package set can differ on linux/amd64, so the OS-layer
picture in production may differ slightly.

This PR fixes: #36546

Clears 9 HIGH/CRITICAL findings from the container image vulnerability scan
(issue #36546) with no API, coordinate, or scope change — every bump stays
within the same major version and the same artifact coordinates.

  tomcat-catalina/jasper/jdbc   9.0.120 -> 9.0.122   (3 CRITICAL)
  org.postgresql:postgresql       42.7.2 -> 42.7.13   (CVE-2026-42198)
  dnsjava:dnsjava                 3.5.3 -> 3.6.5     (CVE-2024-25638, 2x GHSA KeyTrap)
  core5:httpcore5 (+ h2)          5.3.4 -> 5.4.3     (CVE-2026-54399, CVE-2026-54428)
  xstream:xstream               1.4.20 -> 1.4.21    (CVE-2024-47072)
  io.micrometer:*              1.13.10 -> 1.15.12   (CVE-2026-40984)

tomcat.version additionally drives the Tomcat distribution zip fetched by the
assembly and the tomcat-* jars. The 9.0.122 zip and every 9.0.122 artifact were
confirmed present on Maven Central. It does not affect a Docker base image: the
product image builds FROM dotcms/java-base (Java 25), and the docker.base.image
property that names a tomcat image is unreferenced dead config.

Deliberately out of scope: commons-fileupload and grpc (both need code changes;
PR #36548 covers them), ion-java (the fix lives at a different groupId,
com.amazon.ion, while the artifact in use stops at 1.5.1), jackson,
graphql-java, elasticsearch and jdom (breaking upgrades or deliberate pins),
and cryptacular/xmlsec (ship from the dotCMS/com.dotcms.dotsaml repo).

Verified: ./mvnw install -pl :dotcms-core --am -DskipTests succeeds, and
dependency:list resolves all six at the new versions with no superseded
version left in the tree. Committed with HUSKY=0 — the pre-commit hook cannot
run under pnpm 9, and lint-staged only matches core-web TS/JS files.
@claude

claude Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @wezell's task in 1m 9s —— View job


Code Review — dependency version bumps

  • Read the diff (bom/application/pom.xml, parent/pom.xml, environments/environment.properties)
  • Check version consistency across the micrometer/tomcat/httpcore artifact families
  • Check for version-skew or dead-config introduced by the bumps

New Issues

No issues found.

All three files check out:

  • bom/application/pom.xml — six version properties/pins bumped. micrometer.version (1.13.10 → 1.15.12) drives micrometer-bom (imported), micrometer-core, -registry-prometheus, and -registry-jmx — all four resolve through the single property, so the family stays aligned (bom/application/pom.xml:30, :1643-1665). No separate prometheus-simpleclient pin exists to skew against the new Prometheus client, so no version-skew is introduced. httpcore5 + httpcore5-h2 are both moved to 5.4.3 together (:924, :930) — good, mismatched core5 artifacts would have been the real trap here. Postgres, dnsjava, and xstream keep their existing <exclusions> intact.
  • parent/pom.xml:82 — tomcat.version 9.0.120 → 9.0.122, single property that feeds both the distribution zip and every tomcat-* jar, so they stay in lockstep.
  • environments/environment.properties:3-8 — test-only mirror prefix (mirror.gcr.io/…) on the three docker-maven-plugin test images; tags unchanged, no production path. Already reviewed and approved.

Note (non-blocking)

The PR body itself flags it, and I concur: this is a static-consistency pass only — I can confirm the BOM is coherent, but not runtime behavior. The two bumps with real blast radius are micrometer (minor bump feeding the telemetry/metrics system — PrometheusMeterRegistry and the /v1/usage path) and tomcat (the servlet container). A smoke test that boots the container and hits a telemetry endpoint would cover the realistic risk before merge. This is advisory, not a code defect.

· issue-36546-safe-dependency-bumps

@wezell wezell added the PR : dotbot review Trigger dotbot AI code review and the post-merge QA test plan label Sep 18, 2026
@github-actions github-actions Bot added the Area : Backend PR changes Java/Maven backend code label Sep 18, 2026

@dotCMS-Machine-User dotCMS-Machine-User left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ dotbot review: all reviewer models (meta/muse-spark-1.3, ~z-ai/glm-latest) agree — patch is correct.

approved automatically by dotbot

…mirror

The PR test suite failed on a Docker Hub network timeout while pulling
opensearchproject/opensearch:1.3.6:

  [ERROR] DOCKER> Unable to pull 'opensearchproject/opensearch:1.3.6' :
    Head "https://registry-1.docker.io/v2/..." : Get
    "https://auth.docker.io/token?..." : net/http: request canceled
    (Client.Timeout exceeded while awaiting headers) (Internal Server Error: 500)

The docker-maven-plugin pulls this image on every test run, so a failure to
reach Docker Hub takes down the whole PR test phase: one job fails and the rest
are cancelled. Point it at mirror.gcr.io, Google's Docker Hub pull-through
cache, to take registry-1.docker.io and auth.docker.io out of the critical path.

Verified the mirror serves the identical image for this tag — the manifest
digest is the same as Docker Hub's, and the pull succeeds locally.

Scope: only docker.image.search, the image that actually failed. The other
images this file pins (opensearch:3.8.0 for the upgrade suite, pgvector:pg18,
wiremock:3.5.3) are also available on the mirror and can be moved the same way
if the direct pulls prove flaky too; they are left on Docker Hub here to keep
this change to the one that broke.

@dotCMS-Machine-User dotCMS-Machine-User left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ dotbot review: all reviewer models (meta/muse-spark-1.3, ~z-ai/glm-latest) agree — patch is correct.

approved automatically by dotbot

@dotCMS-Machine-User dotCMS-Machine-User left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ dotbot review: all reviewer models (meta/muse-spark-1.3, ~z-ai/glm-latest) agree — patch is correct.

approved automatically by dotbot

@wezell wezell added the PR: docker image Build & push a per-PR test image to dotcms/dotcms-test label Sep 18, 2026
@github-actions

github-actions Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

🐳 PR Docker test image

Latest build for commit 383214e pushed to dotcms/dotcms-test:

docker pull dotcms/dotcms-test:pr-37626-issue-36546-safe-dependency-bumps
docker pull dotcms/dotcms-test:pr-37626-issue-36546-safe-dependency-bumps_383214e

@wezell
wezell added this pull request to the merge queue Sep 18, 2026
@wezell
wezell removed this pull request from the merge queue due to a manual request Sep 18, 2026

@sfreudenthaler sfreudenthaler left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

looks good. should make sure we do a good round of tests cuz there are a few minor semver bumps in there. shouldn’t have breaking change but ya never know

Comment thread environments/environment.properties
@github-actions

Copy link
Copy Markdown
Contributor

dotbot code review:

  • Reviewer: meta/muse-spark-1.3 (medium)
  • Overall: patch is correct
  • New findings this run: 0
  • Prior unresolved dotbot findings still relevant: 0
  • Active findings total: 0

Dependency-only bumps stay within same major version and artifact coordinates with no code changes; prior build verification succeeded and no in-repo caller or contract breakage was found. Test-container image mirror change is test-only with no production impact.

Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads.

reviewed by dotbot · meta/muse-spark-1.3 · medium

@github-actions

Copy link
Copy Markdown
Contributor

dotbot code review:

  • Reviewer: ~z-ai/glm-latest (medium)
  • Overall: patch is correct
  • New findings this run: 0
  • Prior unresolved dotbot findings still relevant: 0
  • Active findings total: 0

The patch only bumps dependency pins within the same major versions and artifact coordinates (micrometer, postgresql, dnsjava, httpcore5/-h2, xstream, tomcat), each driven by a single property, so no version skew is introduced. The environment.properties change applies a pull-through mirror prefix to test-only docker-maven-plugin container images with unchanged tags. No code, API, or contract changes exist in the repo that could break callers.

Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads.

reviewed by dotbot · ~z-ai/glm-latest · medium

@wezell
wezell added this pull request to the merge queue Sep 21, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 21, 2026
@wezell
wezell added this pull request to the merge queue Sep 22, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Sep 22, 2026
@wezell
wezell added this pull request to the merge queue Sep 22, 2026
@wezell
wezell removed this pull request from the merge queue due to a manual request Sep 22, 2026
@wezell
wezell added this pull request to the merge queue Sep 22, 2026
Merged via the queue into main with commit 0803f49 Sep 22, 2026
80 checks passed
@wezell
wezell deleted the issue-36546-safe-dependency-bumps branch September 22, 2026 23:44
@mbiuki mbiuki added CVSS : 9.8 CVSS v3.1 base score 9.8 (Critical) Priority : 1 Show Stopper Team : Security Issues related to security and privacy and removed Priority : 1 Show Stopper labels Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

AI: Safe To Rollback Area : Backend PR changes Java/Maven backend code CVSS : 9.8 CVSS v3.1 base score 9.8 (Critical) PR: docker image Build & push a per-PR test image to dotcms/dotcms-test PR : dotbot review Trigger dotbot AI code review and the post-merge QA test plan Team : Security Issues related to security and privacy

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

Upgrade vulnerable dependencies flagged in security scan (netty, commons-fileupload, grpc)

4 participants