Repository navigation
chore(deps): bump jackson, commons-fileupload, grpc and AWS SDK v1 (#36546) - #37904
Conversation
…36546) - jackson 2.17.2 -> 2.18.11 (core) and 2.21.3 -> 2.21.7 (Tika bundle) - commons-fileupload 1.5 -> 1.6.0; drop the createItem(Map, boolean) overrides in LiferayFileUpload/LiferayDiskFileUpload, which no longer compile against 1.6.0 and haven't been called by FileUploadBase since 1.3 - pin grpc to 1.75.0 via grpc-bom (transitive via langchain4j Vertex AI) - aws-java-sdk v1 1.12.488 -> 1.12.797, which no longer pulls in software.amazon.ion:ion-java Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017K9XDfPM8s7XjLDG2V4LnN
dotCMS-Machine-User
left a comment
There was a problem hiding this comment.
✅ dotbot review: all reviewer models (meta/muse-spark-1.3, ~z-ai/glm-latest) agree — patch is correct.
approved automatically by dotbot
|
Claude finished @erickgonzalez's task in 1m 57s —— View job PR Review — dependency bumps (jackson, commons-fileupload, grpc, AWS SDK v1)
I reviewed the diff against New Issues
Verified / no issues
The two intentional behavior changes the author already called out — commons-fileupload 1.6.0's 512-byte per-part header limit, and jackson 2.18's property-introspection rewrite — are not defects; they're correctly flagged for CI/QA attention. The header limit in particular is a real functional change for very long or multibyte upload filenames on the legacy portlet and push-publish bundle paths, worth a targeted upload smoke test before release. No blocking issues. |
|
dotbot code review:
Dependency-only bumps with compile fixes; removed createItem overrides were unreachable via the FileItemFactory path, header-limit retention is intentional hardening called out in the PR, and version/BOM ordering is correct with no tracked callers broken. Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads. reviewed by dotbot · meta/muse-spark-1.3 · medium |
|
dotbot code review:
Dependency version bumps plus removal of dead createItem overrides. In commons-fileupload 1.5, item creation goes through the FileItemFactory (LiferayFileItemFactory already returns LiferayFileItem), so the removed overrides were unreachable; the FILE_NAME session attribute is never read by remaining code (only removed), so behavior is preserved. The grpc-bom import ordering before langchain4j-bom and the tika-plugin jackson pin are intentional and documented in the diff. Tip: comment with "/dotbot address comments" to attempt automated fixes for unresolved review threads. reviewed by dotbot · ~z-ai/glm-latest · medium |
|
🐳 PR Docker test imageLatest build for commit docker pull dotcms/dotcms-test:pr-37904-issue-36546-dependency-upgrades
docker pull dotcms/dotcms-test:pr-37904-issue-36546-dependency-upgrades_c430b21 |
Pre-merge QA ✅Tested the
The |
|
@ihoffmann-dot heads up that this patch might impact dotai. where’s the best place to test that |
Warning
commons-fileupload 1.6.0rejects upload parts whose headers exceed 512 bytes, which a very long or non-ASCII filename could hit. That limit is the security fix itself, so I kept it. It affects the legacy portlet uploads and the push-publish bundle upload. The PR description calls it out for reviewers.jackson 2.18is a minor upgrade but includes a rewrite of how properties are detected, so watch CI for serialization regressions.Summary
Minor/patch dependency upgrades for libraries with published security fixes.
bom/applicationbom/applicationgrpc-bompin)bom/applicationbom/application(no longer depends onsoftware.amazon.ion:ion-java)Covers the remaining scope of #36548 (its netty part already landed in #37593).
Notes for reviewers
FileUploadBase.createItem(Map, boolean). The overrides inLiferayFileUploadandLiferayDiskFileUploadstopped compiling, so I removed them. They're dead code:parseRequesthasn't called that method since 1.3 (it goes throughFileItemFactory.createItem).UploadServletRequest) and the push-publish bundle upload (RemotePublishAjaxAction). A part whose headers exceed 512 bytes (e.g. a very long or multibyte filename) is now rejected. I left the upstream default in place.Verification
./mvnw compile -pl :dotcms-corepasses;openapi.yamlunchangeddependency:treeconfirms the resolved versions above, andion-javais no longer on the classpathjackson-core/jackson-databind2.21.7Closes: #36546
🤖 Generated with Claude Code
https://claude.ai/code/session_017K9XDfPM8s7XjLDG2V4LnN
This PR fixes: #36546