Skip to content

Remove vulnerable coordinates from the remaining IT fixtures - #1724

Merged
slachiewicz merged 3 commits into
masterfrom
agent/it-fixtures-no-vulnerable-coordinates
Oct 7, 2026
Merged

slachiewicz merged 3 commits into
masterfrom
agent/it-fixtures-no-vulnerable-coordinates

Conversation

@slachiewicz

Copy link
Copy Markdown
Member

Clears the last five Dependabot alerts, all in IT fixtures, without changing what the tests cover.

  • list-repositories and copy-dependencies-with-conflict now depend on mock POMs served by mrm instead of maven-core 3.2.5 and org.jdom:jdom (which has no fixed release). The mock dependency declares the sonatype-nexus-snapshots repository that previously came from maven-core's parent chain; it needs a child node because the collector attaches a POM's repositories to that POM's dependencies.
  • tree-verbose bumps batik-bridge 1.7 → 1.19. Batik only contributed the "omitted for duplicate" diamond, which the new tree keeps; the managed-version and conflict cases come from maven-project 2.0.6.

Verified: mvn -P run-its verify on the three ITs with a clean target → passed under Maven 3.9.16 and 4.0.0-rc-7 (tree-verbose also under 3.9.0).

The fixture only needs a dependency whose POM declares a repository, so
that list-repositories reports it as mirrored. maven-core 3.2.5 provided
that through oss-parent in its POM chain and carries GHSA-2f88-5hg8-9x2x.
The collector attaches descriptor repositories to the child nodes, so the
mock dependency needs a transitive leaf for the repository to show up.
The test needs two artifacts that share artifactId and version under
different groupIds; which artifacts they are does not matter, so serve
them from the mrm mock repository instead of org.jdom:jdom 1.1.3, which
carries an unfixable Dependabot alert (GHSA-2363-cqg2-863c).
batik-bridge only supplies the diamond of 'omitted for duplicate' nodes
below maven-project's managed/conflict cases; 1.19 keeps that coverage
and clears GHSA-rwqr-m72q-v6cm, GHSA-53jm-3hc9-fqqc and GHSA-gq5f-xv48-2365.
Goldens regenerated under Maven 3.9.16 (identical on 3.9.0) and 4.0.0-rc-7.
@slachiewicz slachiewicz added the dependencies Pull requests that update a dependency file label Oct 7, 2026
@slachiewicz
slachiewicz marked this pull request as ready for review October 7, 2026 20:27
@slachiewicz
slachiewicz merged commit 783a3a6 into master Oct 7, 2026
21 checks passed
@slachiewicz
slachiewicz deleted the agent/it-fixtures-no-vulnerable-coordinates branch October 7, 2026 20:48
@github-actions github-actions Bot added this to the 3.12.0 milestone Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant