Skip to content

chore(deps): automated dependency updates 2026-08-31 - #165

Closed
izg-dependency-bot[bot] wants to merge 2 commits into
developfrom
dependency-updates-20260831-13-57
Closed

chore(deps): automated dependency updates 2026-08-31#165
izg-dependency-bot[bot] wants to merge 2 commits into
developfrom
dependency-updates-20260831-13-57

Conversation

@izg-dependency-bot

Copy link
Copy Markdown
Contributor

Automated Dependency Updates

This PR was created automatically by the Automated Dependency Updates workflow.

Version Changes (property-backed)

Property Old Version New Version
aws-sdk 2.54.6 2.54.7

Transitive Dependencies Auto-fixed

None — all transitives are already property-backed.

These transitives had no existing property override. A new <properties> entry and
<dependencyManagement> entry were added automatically for each.

Transitives Requiring Manual Action

None.

These could not be patched automatically. Each requires a manual <properties> entry
and <dependencyManagement> entry in the BOM.

Dependency Tree Changes

145,154c145,154
< [INFO] +- software.amazon.awssdk:secretsmanager:jar:2.54.6:compile
< [INFO] |  +- software.amazon.awssdk:aws-json-protocol:jar:2.54.6:compile
< [INFO] |  |  \- software.amazon.awssdk:third-party-jackson-core:jar:2.54.6:compile
< [INFO] |  +- software.amazon.awssdk:protocol-core:jar:2.54.6:compile
< [INFO] |  +- software.amazon.awssdk:http-auth-aws:jar:2.54.6:compile
< [INFO] |  |  +- software.amazon.awssdk:checksums-spi:jar:2.54.6:compile
< [INFO] |  |  \- software.amazon.awssdk:checksums:jar:2.54.6:compile
< [INFO] |  +- software.amazon.awssdk:sdk-core:jar:2.54.6:compile
< [INFO] |  |  +- software.amazon.awssdk:profiles:jar:2.54.6:compile
< [INFO] |  |  +- software.amazon.awssdk:retries:jar:2.54.6:compile
---
> [INFO] +- software.amazon.awssdk:secretsmanager:jar:2.54.7:compile
> [INFO] |  +- software.amazon.awssdk:aws-json-protocol:jar:2.54.7:compile
> [INFO] |  |  \- software.amazon.awssdk:third-party-jackson-core:jar:2.54.7:compile
> [INFO] |  +- software.amazon.awssdk:protocol-core:jar:2.54.7:compile
> [INFO] |  +- software.amazon.awssdk:http-auth-aws:jar:2.54.7:compile
> [INFO] |  |  +- software.amazon.awssdk:checksums-spi:jar:2.54.7:compile
> [INFO] |  |  \- software.amazon.awssdk:checksums:jar:2.54.7:compile
> [INFO] |  +- software.amazon.awssdk:sdk-core:jar:2.54.7:compile
> [INFO] |  |  +- software.amazon.awssdk:profiles:jar:2.54.7:compile
> [INFO] |  |  +- software.amazon.awssdk:retries:jar:2.54.7:compile
156,157c156,157
< [INFO] |  +- software.amazon.awssdk:auth:jar:2.54.6:compile
< [INFO] |  |  +- software.amazon.awssdk:http-auth-aws-eventstream:jar:2.54.6:compile
---
> [INFO] |  +- software.amazon.awssdk:auth:jar:2.54.7:compile
> [INFO] |  |  +- software.amazon.awssdk:http-auth-aws-eventstream:jar:2.54.7:compile
159,173c159,173
< [INFO] |  +- software.amazon.awssdk:http-auth-spi:jar:2.54.6:compile
< [INFO] |  +- software.amazon.awssdk:http-auth:jar:2.54.6:compile
< [INFO] |  +- software.amazon.awssdk:identity-spi:jar:2.54.6:compile
< [INFO] |  +- software.amazon.awssdk:http-client-spi:jar:2.54.6:compile
< [INFO] |  +- software.amazon.awssdk:regions:jar:2.54.6:compile
< [INFO] |  +- software.amazon.awssdk:annotations:jar:2.54.6:compile
< [INFO] |  +- software.amazon.awssdk:utils:jar:2.54.6:compile
< [INFO] |  +- software.amazon.awssdk:aws-core:jar:2.54.6:compile
< [INFO] |  |  \- software.amazon.awssdk:utils-lite:jar:2.54.6:compile
< [INFO] |  +- software.amazon.awssdk:metrics-spi:jar:2.54.6:compile
< [INFO] |  +- software.amazon.awssdk:json-utils:jar:2.54.6:compile
< [INFO] |  +- software.amazon.awssdk:endpoints-spi:jar:2.54.6:compile
< [INFO] |  +- software.amazon.awssdk:retries-spi:jar:2.54.6:compile
< [INFO] |  +- software.amazon.awssdk:apache5-client:jar:2.54.6:runtime
< [INFO] |  \- software.amazon.awssdk:netty-nio-client:jar:2.54.6:runtime
---
> [INFO] |  +- software.amazon.awssdk:http-auth-spi:jar:2.54.7:compile
> [INFO] |  +- software.amazon.awssdk:http-auth:jar:2.54.7:compile
> [INFO] |  +- software.amazon.awssdk:identity-spi:jar:2.54.7:compile
> [INFO] |  +- software.amazon.awssdk:http-client-spi:jar:2.54.7:compile
> [INFO] |  +- software.amazon.awssdk:regions:jar:2.54.7:compile
> [INFO] |  +- software.amazon.awssdk:annotations:jar:2.54.7:compile
> [INFO] |  +- software.amazon.awssdk:utils:jar:2.54.7:compile
> [INFO] |  +- software.amazon.awssdk:aws-core:jar:2.54.7:compile
> [INFO] |  |  \- software.amazon.awssdk:utils-lite:jar:2.54.7:compile
> [INFO] |  +- software.amazon.awssdk:metrics-spi:jar:2.54.7:compile
> [INFO] |  +- software.amazon.awssdk:json-utils:jar:2.54.7:compile
> [INFO] |  +- software.amazon.awssdk:endpoints-spi:jar:2.54.7:compile
> [INFO] |  +- software.amazon.awssdk:retries-spi:jar:2.54.7:compile
> [INFO] |  +- software.amazon.awssdk:apache5-client:jar:2.54.7:runtime
> [INFO] |  \- software.amazon.awssdk:netty-nio-client:jar:2.54.7:runtime
270,271c270,271
< [INFO] Total time:  1.815 s
< [INFO] Finished at: 2026-08-31T13:55:26Z
---
> [INFO] Total time:  1.689 s
> [INFO] Finished at: 2026-08-31T13:56:55Z

Excluded Libraries (not updated automatically)

  • org.bouncycastle:bc-fips (manually managed — not updated automatically)
  • org.bouncycastle:bcpkix-fips (manually managed — not updated automatically)
  • org.bouncycastle:bctls-fips (manually managed — not updated automatically)

These libraries require manual review before upgrading. Check for major version bumps or certification requirements.

CVE Scan Results

Phase Result
Pre-update Pre-update scan: 1 vulnerabilities found. See the dependency-check-report-pre-update artifact.
Post-update Post-update scan: 1 vulnerabilities found. See the dependency-check-report-post-update artifact.

See the dependency-check-report-pre-update and dependency-check-report-post-update artifacts for full details.

Notes

  • Only patch and minor version bumps are applied automatically (allowMajorUpdates=false).
  • All updated versions have been verified to resolve via mvn dependency:resolve on the validation project.
  • Transitives that could not be auto-fixed are flagged above and require a manual BOM entry.

austinmoody and others added 2 commits August 31, 2026 09:19
The 2026-08-31 nightly failed its post-update CVE scan. The 7 camel CVEs
fixed by 4.18.4 are gone; this is a new finding published since.

CVE-2026-66908 (CVSS 7.5) is in the Apache Camel Platform HTTP Main
component: the camel-main embedded HTTP server built Vert.x JWTAuth from
the keystore alone when neither jwtIssuer nor jwtAudience was set, so
inbound tokens were checked only for signature and expiry. See
CAMEL-24281.

No upgrade clears it on our line. The advisory is explicit: "This
behaviour is fixed only on 4.22.0 ... The fail-closed guard could not be
backported." 4.18.4 is the newest 4.18.x release.

Camel 4.22.0 is not available to us. camel-spring-boot switched to Spring
Boot 4 at 4.19.0: 4.19.0 and 4.20.0 resolve Spring Boot 4.0.5, 4.21.0 and
4.22.0 resolve Spring Boot 4.1.0 with Spring Framework 7.0.8. Pinning
Spring Boot 3.5.16 underneath camel 4.22.0 resolves cleanly but does not
run — camel-spring-boot-4.22.0.jar is compiled against Spring Boot 4
package locations that do not exist in 3.5.16:

  org.springframework.boot.EnvironmentPostProcessor
    -> 3.5.16 has org.springframework.boot.env.EnvironmentPostProcessor
  org.springframework.boot.tomcat.servlet.TomcatServletWebServerFactory
    -> 3.5.16 has
       org.springframework.boot.web.embedded.tomcat.TomcatServletWebServerFactory

Both ship in the core spring-boot artifact, which is on the classpath at
3.5.16, so these are NoClassDefFoundError at startup, not unresolved
optional jars. izgw-core, izgw-hub, izgw-transform and v2tofhir all take
this BOM as parent and none declares its own spring-boot.version, so
moving off 3.5.x is a coordinated four-repo major upgrade.

Suppress with an expiry of 2027-02-28 to put a date on that decision.
The vulnerable code is not on the classpath: camel-platform-http-main and
io.vertx are absent from both the BOM validation tree and izgw-transform,
and camel-main-4.18.4.jar carries no JWT, platform-http or Vert.x classes.
Matched on <cve> alone. Per the suppression XSD, <cpe> is a suppress-what
element rather than a dependency selector, so keying on
cpe:/a:apache:camel would have hidden every camel finding including future
ones.

Also remove the CVE-2026-54285 opentelemetry entry added in fa8bd73. It
never matched: it was keyed on <packageUrl>, but opentelemetry-api ships
no META-INF/maven (the Java client builds with Gradle) so Dependency-Check
derives no purl for it. Rather than re-key it, let the finding stand. At
CVSS 5.3 it is below the --failOnCVSS 7 gate, so it never fails a build;
it sets HAS_CVES, which labels the nightly PR "security" and leaves it for
a human to merge. That is the intended behaviour of that gate.

Verified: xmllint --schema dependency-suppression.1.3.xsd validates.
Suppression matching itself is unverified locally — Dependency-Check needs
the NVD database and an API key. Confirm with a workflow_dispatch run.
@izg-dependency-bot izg-dependency-bot Bot added dependencies Pull requests that update a dependency file security labels Aug 31, 2026
@austinmoody

Copy link
Copy Markdown
Contributor

Closing because this was a test run out of a branch to test suppression.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant