Skip to content

chore(deps): automated dependency updates 2026-08-28 - #162

Merged
austinmoody merged 2 commits into
developfrom
dependency-updates-20260828-13-28
Aug 28, 2026
Merged

chore(deps): automated dependency updates 2026-08-28#162
austinmoody merged 2 commits into
developfrom
dependency-updates-20260828-13-28

Conversation

@izg-dependency-bot

Copy link
Copy Markdown
Contributor

Automated Dependency Updates

This PR was created automatically by the Automated Dependency Updates workflow.

Version Changes (property-backed)

Property Old Version New Version
aws-sdk 2.54.5 2.54.6

Transitive Dependencies Auto-fixed

None — all transitives are already property-backed.

These transitives had no existing property override. A new <properties> entry and
<dependencyManagement> entry were added automatically for each.

Transitives Requiring Manual Action

None.

These could not be patched automatically. Each requires a manual <properties> entry
and <dependencyManagement> entry in the BOM.

Dependency Tree Changes

145,154c145,154
< [INFO] +- software.amazon.awssdk:secretsmanager:jar:2.54.5:compile
< [INFO] |  +- software.amazon.awssdk:aws-json-protocol:jar:2.54.5:compile
< [INFO] |  |  \- software.amazon.awssdk:third-party-jackson-core:jar:2.54.5:compile
< [INFO] |  +- software.amazon.awssdk:protocol-core:jar:2.54.5:compile
< [INFO] |  +- software.amazon.awssdk:http-auth-aws:jar:2.54.5:compile
< [INFO] |  |  +- software.amazon.awssdk:checksums-spi:jar:2.54.5:compile
< [INFO] |  |  \- software.amazon.awssdk:checksums:jar:2.54.5:compile
< [INFO] |  +- software.amazon.awssdk:sdk-core:jar:2.54.5:compile
< [INFO] |  |  +- software.amazon.awssdk:profiles:jar:2.54.5:compile
< [INFO] |  |  +- software.amazon.awssdk:retries:jar:2.54.5:compile
---
> [INFO] +- software.amazon.awssdk:secretsmanager:jar:2.54.6:compile
> [INFO] |  +- software.amazon.awssdk:aws-json-protocol:jar:2.54.6:compile
> [INFO] |  |  \- software.amazon.awssdk:third-party-jackson-core:jar:2.54.6:compile
> [INFO] |  +- software.amazon.awssdk:protocol-core:jar:2.54.6:compile
> [INFO] |  +- software.amazon.awssdk:http-auth-aws:jar:2.54.6:compile
> [INFO] |  |  +- software.amazon.awssdk:checksums-spi:jar:2.54.6:compile
> [INFO] |  |  \- software.amazon.awssdk:checksums:jar:2.54.6:compile
> [INFO] |  +- software.amazon.awssdk:sdk-core:jar:2.54.6:compile
> [INFO] |  |  +- software.amazon.awssdk:profiles:jar:2.54.6:compile
> [INFO] |  |  +- software.amazon.awssdk:retries:jar:2.54.6:compile
156,157c156,157
< [INFO] |  +- software.amazon.awssdk:auth:jar:2.54.5:compile
< [INFO] |  |  +- software.amazon.awssdk:http-auth-aws-eventstream:jar:2.54.5:compile
---
> [INFO] |  +- software.amazon.awssdk:auth:jar:2.54.6:compile
> [INFO] |  |  +- software.amazon.awssdk:http-auth-aws-eventstream:jar:2.54.6:compile
159,173c159,173
< [INFO] |  +- software.amazon.awssdk:http-auth-spi:jar:2.54.5:compile
< [INFO] |  +- software.amazon.awssdk:http-auth:jar:2.54.5:compile
< [INFO] |  +- software.amazon.awssdk:identity-spi:jar:2.54.5:compile
< [INFO] |  +- software.amazon.awssdk:http-client-spi:jar:2.54.5:compile
< [INFO] |  +- software.amazon.awssdk:regions:jar:2.54.5:compile
< [INFO] |  +- software.amazon.awssdk:annotations:jar:2.54.5:compile
< [INFO] |  +- software.amazon.awssdk:utils:jar:2.54.5:compile
< [INFO] |  +- software.amazon.awssdk:aws-core:jar:2.54.5:compile
< [INFO] |  |  \- software.amazon.awssdk:utils-lite:jar:2.54.5:compile
< [INFO] |  +- software.amazon.awssdk:metrics-spi:jar:2.54.5:compile
< [INFO] |  +- software.amazon.awssdk:json-utils:jar:2.54.5:compile
< [INFO] |  +- software.amazon.awssdk:endpoints-spi:jar:2.54.5:compile
< [INFO] |  +- software.amazon.awssdk:retries-spi:jar:2.54.5:compile
< [INFO] |  +- software.amazon.awssdk:apache5-client:jar:2.54.5:runtime
< [INFO] |  \- software.amazon.awssdk:netty-nio-client:jar:2.54.5:runtime
---
> [INFO] |  +- software.amazon.awssdk:http-auth-spi:jar:2.54.6:compile
> [INFO] |  +- software.amazon.awssdk:http-auth:jar:2.54.6:compile
> [INFO] |  +- software.amazon.awssdk:identity-spi:jar:2.54.6:compile
> [INFO] |  +- software.amazon.awssdk:http-client-spi:jar:2.54.6:compile
> [INFO] |  +- software.amazon.awssdk:regions:jar:2.54.6:compile
> [INFO] |  +- software.amazon.awssdk:annotations:jar:2.54.6:compile
> [INFO] |  +- software.amazon.awssdk:utils:jar:2.54.6:compile
> [INFO] |  +- software.amazon.awssdk:aws-core:jar:2.54.6:compile
> [INFO] |  |  \- software.amazon.awssdk:utils-lite:jar:2.54.6:compile
> [INFO] |  +- software.amazon.awssdk:metrics-spi:jar:2.54.6:compile
> [INFO] |  +- software.amazon.awssdk:json-utils:jar:2.54.6:compile
> [INFO] |  +- software.amazon.awssdk:endpoints-spi:jar:2.54.6:compile
> [INFO] |  +- software.amazon.awssdk:retries-spi:jar:2.54.6:compile
> [INFO] |  +- software.amazon.awssdk:apache5-client:jar:2.54.6:runtime
> [INFO] |  \- software.amazon.awssdk:netty-nio-client:jar:2.54.6:runtime
270,271c270,271
< [INFO] Total time:  1.774 s
< [INFO] Finished at: 2026-08-28T13:26:46Z
---
> [INFO] Total time:  1.789 s
> [INFO] Finished at: 2026-08-28T13:28:13Z

Excluded Libraries (not updated automatically)

  • org.bouncycastle:bc-fips (manually managed — not updated automatically)
  • org.bouncycastle:bcpkix-fips (manually managed — not updated automatically)
  • org.bouncycastle:bctls-fips (manually managed — not updated automatically)

These libraries require manual review before upgrading. Check for major version bumps or certification requirements.

CVE Scan Results

Phase Result
Pre-update Pre-update scan: 1 vulnerabilities found. See the dependency-check-report-pre-update artifact.
Post-update Post-update scan: 1 vulnerabilities found. See the dependency-check-report-post-update artifact.

See the dependency-check-report-pre-update and dependency-check-report-post-update artifacts for full details.

Notes

  • Only patch and minor version bumps are applied automatically (allowMajorUpdates=false).
  • All updated versions have been verified to resolve via mvn dependency:resolve on the validation project.
  • Transitives that could not be auto-fixed are flagged above and require a manual BOM entry.

austinmoody and others added 2 commits August 28, 2026 09:23
The 2026-08-28 nightly failed its post-update CVE scan with 8 findings:
7 in camel-core-engine 4.18.3, up to CRITICAL, plus one MEDIUM.

Bump camel.version to 4.18.4, the 4.18.x LTS patch that fixes all 7
(CVE-2026-71300, -78329, -66906, -66907, -59230, -60093, -63621).

Do not follow the advisories to 4.22.0. Camel 4.19.0 and later build
against Spring Boot 4: 4.19.0 and 4.20.0 pull Spring Boot 4.0.5, 4.21.0
and 4.22.0 pull Spring Boot 4.1.0 with Spring Framework 7. This BOM pins
spring-boot.version on 3.5.x, so 4.18.4 is the only version that clears
all 7 and keeps Spring Boot 3. versions-rules.xml now caps Camel at
4.18.x so the automation cannot cross that line on its own.

Root cause of the stale version: the dependencyManagement entry declared
org.apache.camel:camel-spring-boot-starter. The correct groupId is
org.apache.camel.springboot. The org.apache.camel coordinate exists on
Central but stops at 3.0.0-RC3, and versions-rules.xml ignores RC
versions, so versions-maven-plugin found no acceptable version for one
artifact on ${camel.version} and logged "Leaving unchanged as 4.18.3"
every night. camel.version has been silently unmaintained. The starter
is now also declared in validation/pom.xml, so the coordinate is
resolution-checked and CVE-scanned.

Suppress the remaining MEDIUM, CVE-2026-54285, as a wrong-ecosystem CPE
match. It is an opentelemetry-js flaw in the @opentelemetry/core npm
package; NVD scopes it to target_sw=node.js, but Dependency-Check derives
a target_sw-less CPE for the Java jars, so the wildcard matches. No Node
OpenTelemetry ships here, and no Java release can satisfy the "fixed in
2.8.0" range. The entry is keyed on packageUrl rather than sha1 so it
survives an opentelemetry.version bump, is pinned to this one CVE, and
expires 2027-02-28 to force a re-review.

Verified locally:
  mvn -B validate                                  BUILD SUCCESS
  mvn -B clean package -f validation/pom.xml       BUILD SUCCESS
  xmllint --schema dependency-suppression.1.3.xsd  validates
  dependency:tree  camel-core 4.18.4,
                   camel-spring-boot-starter 4.18.4,
                   spring-boot 3.5.16, spring-core 6.2.19 (unchanged)
  versions:display-property-updates
                   ${camel.version} ... 4.18.4 (newest available)
@izg-dependency-bot izg-dependency-bot Bot added dependencies Pull requests that update a dependency file security labels Aug 28, 2026
@austinmoody
austinmoody merged commit 06fc409 into develop Aug 28, 2026
1 check passed
@austinmoody
austinmoody deleted the dependency-updates-20260828-13-28 branch August 28, 2026 13:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant