Skip to content

Compatibility for Gradle > 7 - #12

Open
patrikk0123 wants to merge 2 commits into
project-ncl:masterfrom
patrikk0123:fixSca
Open

Compatibility for Gradle > 7#12
patrikk0123 wants to merge 2 commits into
project-ncl:masterfrom
patrikk0123:fixSca

Conversation

@patrikk0123

Copy link
Copy Markdown
Member
  • All tests passed. If this feature is not already covered by the tests, I added new tests.
  • This pull request is on the dev branch.

@patrikk0123

Copy link
Copy Markdown
Member Author

@github-actions

github-actions Bot commented Jul 8, 2026

Copy link
Copy Markdown

Mend Scan Results

Status: ⚠️ Findings detected

⚠️ SCA findings detected

SCA scan output



Identified 23 dependencies

Detected 7 vulnerabilities (0 Critical, 2 High, 5 Medium, 0 Low)

+----------+-----------------------------+----------------+------------------------------------------------------------------------------------------------+
| SEVERITY |           LIBRARY           |       ID       |                                            TOP FIX                                             |
+----------+-----------------------------+----------------+------------------------------------------------------------------------------------------------+
| HIGH     | jackson-databind-2.21.1.jar | CVE-2026-54512 | Upgrade to version  https://github.com/FasterXML/jackson-databind.git -                        |
|          |                             |                | jackson-databind-2.18.8                                                                        |
+----------+-----------------------------+----------------+------------------------------------------------------------------------------------------------+
| HIGH     | jackson-databind-2.21.1.jar | CVE-2026-54513 | Upgrade to version  https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4 |
+----------+-----------------------------+----------------+------------------------------------------------------------------------------------------------+
| MEDIUM   | jackson-databind-2.21.1.jar | CVE-2026-54514 | Upgrade to version  https://github.com/FasterXML/jackson-databind.git -                        |
|          |                             |                | jackson-databind-2.18.8                                                                        |
+----------+-----------------------------+----------------+------------------------------------------------------------------------------------------------+
| MEDIUM   | jackson-databind-2.21.1.jar | CVE-2026-54515 | Upgrade to version  https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4 |
+----------+-----------------------------+----------------+------------------------------------------------------------------------------------------------+
| MEDIUM   | jackson-databind-2.21.1.jar | CVE-2026-54516 | Upgrade to version  https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4 |
+----------+-----------------------------+----------------+------------------------------------------------------------------------------------------------+
| MEDIUM   | jackson-databind-2.21.1.jar | CVE-2026-54517 | Upgrade to version  https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4 |
+----------+-----------------------------+----------------+------------------------------------------------------------------------------------------------+
| MEDIUM   | jackson-databind-2.21.1.jar | CVE-2026-54518 | Upgrade to version  https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4 |
+----------+-----------------------------+----------------+------------------------------------------------------------------------------------------------+


Paths at risk

P = policy violation
MSC = malicious vulnerability
CRITICAL/HIGH/MEDIUM/LOW = vulnerability severity

jackson-databind-2.21.1.jar [2 HIGH, 5 MEDIUM]
|-- jackson-bom-2.21.1.pom
	|-- jackson-databind-2.21.1.jar [2 HIGH, 5 MEDIUM]
build-info-api-2.43.9.jar
|-- jackson-databind-2.21.1.jar [2 HIGH, 5 MEDIUM]
file-specs-java-1.1.2.jar
|-- jackson-databind-2.21.1.jar [2 HIGH, 5 MEDIUM]
jackson-databind-2.21.1.jar [2 HIGH, 5 MEDIUM]
|-- jackson-bom-2.21.1.pom
	|-- jackson-databind-2.21.1.jar [2 HIGH, 5 MEDIUM]
build-info-api-2.43.9.jar
|-- jackson-databind-2.21.1.jar [2 HIGH, 5 MEDIUM]
file-specs-java-1.1.2.jar
|-- jackson-databind-2.21.1.jar [2 HIGH, 5 MEDIUM]
jackson-databind-2.21.1.jar [2 HIGH, 5 MEDIUM]
|-- jackson-bom-2.21.1.pom
	|-- jackson-databind-2.21.1.jar [2 HIGH, 5 MEDIUM]
artifactory-java-client-api-2.21.3-SNAPSHOT.jar
|-- jackson-databind-2.21.1.jar [2 HIGH, 5 MEDIUM]
artifactory-java-client-httpClient-2.21.3-SNAPSHOT.jar
|-- jackson-databind-2.21.1.jar [2 HIGH, 5 MEDIUM]
build-info-api-2.43.9.jar
|-- jackson-databind-2.21.1.jar [2 HIGH, 5 MEDIUM]
file-specs-java-1.1.2.jar
|-- jackson-databind-2.21.1.jar [2 HIGH, 5 MEDIUM]


No Policy violations were detected

Project 'artifactory-client-java' was updated, for more information, visit the Mend platform: https://ibmets.whitesourcesoftware.com/app/orgs/Enterprise%20Applications/applications/summary?project=13c37c70-9429-4d82-93b5-00c28c8b72ac
Or the Core UI: https://ibmets.whitesourcesoftware.com/Wss/WSS.html#!project;token=49fde329dfa0483582951d6e01055010f2cf94f7b5e34f0797b31063cd346eaa

Mend AI scan succeeded.

Support Token: 285f1ba8ab98c4e899c34d628476defb51783517771536
SAST scan output
*no findings*

Full logs and artifacts

@patrikk0123 patrikk0123 changed the title Turn off artifactory publishing for gradle >= 8 Turn off artifact publishing for gradle >= 8 Jul 8, 2026
@patrikk0123 patrikk0123 changed the title Turn off artifact publishing for gradle >= 8 Compatibility for Gradle > 7 Jul 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant