adobe / adobe/experience-platform-streaming-connect
CVEs Fix
- Dominant language
- Java
- Stars
- 25
- Forks
- 25
- PR merge metrics
- No merged PRs in 30d
Description
Library | From → To | Findings Cleared
-- | -- | --
commons-codec | 1.11 → 1.18.0 | 1 (BDSA-2012-0001)
commons-lang3 | 3.9 → 3.18.0 | 1 (CVE-2025-48924)
jackson-core | 2.14.0 → 2.21.3 | 4 (CVE-2025-52999, BDSA-2022-4307, BDSA-2025-5555, GHSA-72hv-8253-57qq)
jackson-databind | 2.14.0 → 2.21.3 | Keep aligned with jackson-core via jackson-bom
jackson-databind (CVE-2023-35116) | N/A | Suppress — disputed, no fix exists
Library From → To Findings Cleared
commons-codec 1.11 → 1.18.0 1 (BDSA-2012-0001)
commons-lang3 3.9 → 3.18.0 1 (https://github.com/advisories/GHSA-j288-q9x7-2f5v)
jackson-core 2.14.0 → 2.21.3 4 (https://github.com/advisories/GHSA-h46c-h94j-95f3, BDSA-2022-4307, BDSA-2025-5555, https://github.com/advisories/GHSA-72hv-8253-57qq)
jackson-databind 2.14.0 → 2.21.3 Keep aligned with jackson-core via jackson-bom
jackson-databind (https://github.com/advisories/GHSA-gx6w-fqg7-mc3p) N/A Suppress — disputed, no fix exists
Contributor guide
Research direction
The issue names commons-codec, commons-lang3, jackson-core, jackson-databind, and jackson-bom, but no files or tests. Locate the Java dependency manifest, review the current versions and vulnerability findings, then run the repository's available build or dependency checks. Done means the listed findings are cleared and the disputed jackson-databind finding is suppressed as requested.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100