Skip to content

Bump org.jboss.logging:jboss-logging from 3.4.3.Final to 3.6.3.Final - #77

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/org.jboss.logging-jboss-logging-3.6.3.Final
Open

Bump org.jboss.logging:jboss-logging from 3.4.3.Final to 3.6.3.Final#77
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/org.jboss.logging-jboss-logging-3.6.3.Final

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 9, 2026

Copy link
Copy Markdown
Contributor

Bumps org.jboss.logging:jboss-logging from 3.4.3.Final to 3.6.3.Final.

Release notes

Sourced from org.jboss.logging:jboss-logging's releases.

v3.6.3.Final

What's Changed

Full Changelog: jboss-logging/jboss-logging@v3.6.2.Final...v3.6.3.Final

v3.6.2.Final

What's Changed

Full Changelog: jboss-logging/jboss-logging@3.6.1.Final...v3.6.2.Final

3.6.1.Final

What's Changed

... (truncated)

Commits
  • ccb7d0a [maven-release-plugin] prepare release v3.6.3.Final
  • 5528719 Remove the central-release profile that is now in the jboss-parent POM.
  • 9d60d6e Merge pull request #179 from jboss-logging/dependabot/maven/org.jboss-jboss-p...
  • f8aa165 Merge pull request #180 from jboss-logging/dependabot/maven/ch.qos.logback-lo...
  • 9826676 Merge pull request #182 from jboss-logging/dependabot/github_actions/actions/...
  • 02b7a1f [JBLOGGING-203] Merge pull request #183 from dmlloyd/add-reads
  • 2c3ff32 Fix incomplete access issue
  • 0f628e1 Bump actions/upload-artifact from 6 to 7
  • 1bde07c Bump ch.qos.logback:logback-classic from 1.5.28 to 1.5.32
  • c0d4cdf Bump org.jboss:jboss-parent from 51 to 52
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.jboss.logging:jboss-logging](https://github.com/jboss-logging/jboss-logging) from 3.4.3.Final to 3.6.3.Final.
- [Release notes](https://github.com/jboss-logging/jboss-logging/releases)
- [Commits](jboss-logging/jboss-logging@3.4.3.Final...v3.6.3.Final)

---
updated-dependencies:
- dependency-name: org.jboss.logging:jboss-logging
  dependency-version: 3.6.3.Final
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Sep 9, 2026
@github-actions

github-actions Bot commented Sep 9, 2026

Copy link
Copy Markdown

Mend Scan Results

Status: ⚠️ Findings detected

⚠️ SCA findings detected

SCA scan output



Identified 142 dependencies

Detected 10 vulnerabilities (0 Critical, 7 High, 2 Medium, 1 Low)

+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| SEVERITY |            LIBRARY             |       ID       |                                               TOP FIX                                               |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| HIGH     | parsson-1.1.5.jar              | CVE-2026-9563  | Upgrade to version org.eclipse.parsson:parsson:1.1.8, https://github.com/eclipse-ee4j/parsson.git - |
|          |                                |                | 1.1.8                                                                                               |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| HIGH     | plexus-utils-3.5.1.jar         | CVE-2025-67030 | org.codehaus.plexus:plexus-utils:4.0.3,org.codehaus.plexus:plexus-utils:3.6.1                       |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| HIGH     | quarkus-core-3.6.9.jar         | CVE-2024-2700  | Upgrade to version io.quarkus:quarkus-core:3.8.4,3.9.2,3.2.12.Final                                 |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.3.24.Final.jar | CVE-2026-15554 | N/A                                                                                                 |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.3.24.Final.jar | CVE-2026-15561 | N/A                                                                                                 |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.3.24.Final.jar | CVE-2026-5680  | Upgrade to version  https://github.com/undertow-io/undertow.git - 2.4.3.Final,                      |
|          |                                |                | io.undertow:undertow-core:2.4.3.Final                                                               |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| HIGH     | xstream-1.4.20.jar             | CVE-2024-47072 | Upgrade to version com.thoughtworks.xstream:xstream - 1.4.21                                        |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| MEDIUM   | commons-lang3-3.13.0.jar       | CVE-2025-48924 | Upgrade to version  https://github.com/apache/commons-lang.git - commons-lang-3.18.0,               |
|          |                                |                | org.apache.commons:commons-lang3:3.18.0                                                             |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| MEDIUM   | undertow-core-2.3.24.Final.jar | CVE-2026-19879 | N/A                                                                                                 |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+
| LOW      | jansi-2.4.0.jar                | CVE-2026-8484  | N/A                                                                                                 |
+----------+--------------------------------+----------------+-----------------------------------------------------------------------------------------------------+


Paths at risk

P = policy violation
MSC = malicious vulnerability
CRITICAL/HIGH/MEDIUM/LOW = vulnerability severity

http-testserver-core-2.3.4-SNAPSHOT.jar
|-- commons-io-2.15.1.jar
	|-- commons-lang3-3.13.0.jar [1 MEDIUM]
|-- undertow-core-2.3.24.Final.jar [3 HIGH, 1 MEDIUM]
|-- undertow-servlet-2.3.24.Final.jar
	|-- undertow-core-2.3.24.Final.jar [3 HIGH, 1 MEDIUM]
|-- commons-lang3-3.13.0.jar [1 MEDIUM]
|-- httpclient-4.5.14.jar
	|-- commons-codec-1.16.0.jar
		|-- commons-lang3-3.13.0.jar [1 MEDIUM]
http-testserver-junit4-2.3.4-SNAPSHOT.jar
|-- http-testserver-core-2.3.4-SNAPSHOT.jar
	|-- commons-io-2.15.1.jar
		|-- commons-lang3-3.13.0.jar [1 MEDIUM]
	|-- undertow-core-2.3.24.Final.jar [3 HIGH, 1 MEDIUM]
	|-- undertow-servlet-2.3.24.Final.jar
		|-- undertow-core-2.3.24.Final.jar [3 HIGH, 1 MEDIUM]
	|-- commons-lang3-3.13.0.jar [1 MEDIUM]
	|-- httpclient-4.5.14.jar
		|-- commons-codec-1.16.0.jar
			|-- commons-lang3-3.13.0.jar [1 MEDIUM]
http-testserver-junit5-2.3.4-SNAPSHOT.jar
|-- http-testserver-core-2.3.4-SNAPSHOT.jar
	|-- commons-io-2.15.1.jar
		|-- commons-lang3-3.13.0.jar [1 MEDIUM]
	|-- undertow-core-2.3.24.Final.jar [3 HIGH, 1 MEDIUM]
	|-- undertow-servlet-2.3.24.Final.jar
		|-- undertow-core-2.3.24.Final.jar [3 HIGH, 1 MEDIUM]
	|-- commons-lang3-3.13.0.jar [1 MEDIUM]
	|-- httpclient-4.5.14.jar
		|-- commons-codec-1.16.0.jar
			|-- commons-lang3-3.13.0.jar [1 MEDIUM]
http-testserver-quarkus-2.3.4-SNAPSHOT.jar
|-- quarkus-arc-deployment-3.6.9.jar
	|-- quarkus-arc-3.6.9.jar
		|-- quarkus-core-3.6.9.jar [1 HIGH]
	|-- quarkus-core-deployment-3.6.9.jar
		|-- quarkus-bootstrap-maven-resolver-3.6.9.jar
			|-- smallrye-beanbag-maven-1.3.2.jar
				|-- commons-lang3-3.13.0.jar [1 MEDIUM]
				|-- wagon-http-shared-3.5.3.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- wagon-provider-api-3.5.3.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- maven-artifact-3.9.6.jar
					|-- commons-lang3-3.13.0.jar [1 MEDIUM]
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- maven-model-builder-3.9.6.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- maven-repository-metadata-3.9.6.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- plexus-sec-dispatcher-2.0.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- plexus-utils-3.5.1.jar [1 HIGH]
			|-- maven-resolver-transport-wagon-1.9.18.jar
				|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- plexus-xml-4.0.0.jar
					|-- maven-xml-impl-4.0.0-alpha-5.jar
						|-- plexus-utils-3.5.1.jar [1 HIGH]
			|-- wagon-file-3.5.3.jar
				|-- plexus-utils-3.5.1.jar [1 HIGH]
			|-- maven-embedder-3.9.6.jar
				|-- commons-lang3-3.13.0.jar [1 MEDIUM]
				|-- maven-shared-utils-3.3.4.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
					|-- jansi-2.4.0.jar [1 LOW]
				|-- maven-core-3.9.6.jar
					|-- commons-lang3-3.13.0.jar [1 MEDIUM]
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- maven-plugin-api-3.9.6.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- maven-settings-3.9.6.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- jansi-2.4.0.jar [1 LOW]
			|-- maven-resolver-provider-3.9.6.jar
				|-- maven-model-3.9.6.jar
					|-- plexus-utils-3.5.1.jar [1 HIGH]
				|-- plexus-utils-3.5.1.jar [1 HIGH]
			|-- maven-settings-builder-3.9.6.jar
				|-- plexus-utils-3.5.1.jar [1 HIGH]
			|-- org.eclipse.sisu.plexus-0.9.0.M2.jar
				|-- plexus-utils-3.5.1.jar [1 HIGH]
		|-- quarkus-core-3.6.9.jar [1 HIGH]
		|-- readline-2.4.jar
			|-- jansi-2.4.0.jar [1 LOW]
		|-- commons-lang3-3.13.0.jar [1 MEDIUM]
|-- quarkus-junit5-3.6.9.jar
	|-- xstream-1.4.20.jar [1 HIGH]
	|-- quarkus-core-3.6.9.jar [1 HIGH]
|-- http-testserver-core-2.3.4-SNAPSHOT.jar
	|-- commons-io-2.15.1.jar
		|-- commons-lang3-3.13.0.jar [1 MEDIUM]
	|-- undertow-core-2.3.24.Final.jar [3 HIGH, 1 MEDIUM]
		|-- jboss-logmanager-3.0.4.Final.jar
			|-- parsson-1.1.5.jar [1 HIGH]
	|-- undertow-servlet-2.3.24.Final.jar
		|-- undertow-core-2.3.24.Final.jar [3 HIGH, 1 MEDIUM]
	|-- commons-lang3-3.13.0.jar [1 MEDIUM]
	|-- httpclient-4.5.14.jar
		|-- commons-codec-1.16.0.jar
			|-- commons-lang3-3.13.0.jar [1 MEDIUM]


No Policy violations were detected

Project 'http-testserver' was updated, for more information, visit the Mend platform: https://ibmets.whitesourcesoftware.com/app/orgs/Enterprise%20Applications/applications/summary?project=3e4a4791-bd78-42c2-810a-0fe36f078b23
Or the Core UI: https://ibmets.whitesourcesoftware.com/Wss/WSS.html#!project;token=377f5a0ae9fd4922a9e55480620df3a0685d6038dc7f41849565798974f4e93d

Mend AI scan succeeded.

Support Token: 2cd6baddb4633485a81e4915bd2af90af1788943068371

Full logs and artifacts

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants