Conversation
a52eac2 to
0bb2816
Compare
0bb2816 to
d159a9c
Compare
f15fa1f to
1211d88
Compare
1211d88 to
b8b17c1
Compare
|
ab749d2 to
b8b17c1
Compare
|
You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool. What Enabling Code Scanning Means:
For more information about GitHub Code Scanning, check out |
| com.charleskorn.kaml:kaml-jvm:0.59.0=compileClasspath,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testRuntimeClasspath | ||
| com.charleskorn.kaml:kaml:0.59.0=compileClasspath,implementationDependenciesMetadata,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testImplementationDependenciesMetadata,testRuntimeClasspath | ||
| com.fasterxml.jackson.core:jackson-annotations:2.19.4=compileClasspath,implementationDependenciesMetadata,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testImplementationDependenciesMetadata,testRuntimeClasspath | ||
| com.fasterxml.jackson.core:jackson-core:2.19.4=compileClasspath,implementationDependenciesMetadata,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testImplementationDependenciesMetadata,testRuntimeClasspath |
Check failure
Code scanning / Trivy
jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition High
| org.antlr:antlr4:4.7.2=compileClasspath,implementationDependenciesMetadata,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testImplementationDependenciesMetadata,testRuntimeClasspath | ||
| org.apache.commons:commons-compress:1.28.0=compileClasspath,implementationDependenciesMetadata,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testImplementationDependenciesMetadata,testRuntimeClasspath | ||
| org.apache.commons:commons-csv:1.10.0=productionRuntimeClasspath,runtimeClasspath,testRuntimeClasspath | ||
| org.apache.commons:commons-lang3:3.17.0=compileClasspath,implementationDependenciesMetadata,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testImplementationDependenciesMetadata,testRuntimeClasspath |
Check warning
Code scanning / Trivy
commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang Medium
| org.apache.commons:commons-csv:1.10.0=productionRuntimeClasspath,runtimeClasspath,testRuntimeClasspath | ||
| org.apache.commons:commons-lang3:3.17.0=compileClasspath,implementationDependenciesMetadata,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testImplementationDependenciesMetadata,testRuntimeClasspath | ||
| org.apache.logging.log4j:log4j-api:2.24.3=compileClasspath,implementationDependenciesMetadata,productionRuntimeClasspath,runtimeClasspath,testCompileClasspath,testImplementationDependenciesMetadata,testRuntimeClasspath | ||
| org.apache.logging.log4j:log4j-core:2.24.3=productionRuntimeClasspath,runtimeClasspath,testRuntimeClasspath |
Check warning
Code scanning / Trivy
Apache Log4j: Apache Log4j Core: Information disclosure via missing TLS hostname verification Medium



Add image and repo scan for test and publish workflows.
Update spring boot core to
3.5.10Update python libs (experiments)
Clean openapi generator configuration. It avoids the generation of a pom.xml file which is not used and has outdated libraries and vulnerabilities.
Add gradle.lockfile for Java/Kotlin scanning