Problem
The core and processor module POMs pin several dependency versions that have newer releases available. Most notably the only shipped runtime dependency with an available update is JBoss Roaster. A mvn versions:display-dependency-updates audit reports:
| Dependency |
Scope |
Current |
Available |
org.jboss.forge.roaster:roaster-api / roaster-jdt |
runtime (processor) |
2.31.0.Final |
2.31.1.Final |
com.fasterxml.jackson.core:jackson-databind |
test (processor) |
2.21.1 |
2.22.1 |
org.junit.jupiter:junit-jupiter-* |
test (core, processor) |
6.0.3 |
6.1.2 |
commons-lang3 (3.20.0), commons-collections4 (4.5.0), auto-service (1.1.1) and compile-testing (0.23.0) are already current.
Why it matters (high-security / high-reliability use)
For a library consumed as a compile-time dependency, keeping the shipped runtime dependency (Roaster) on the latest patch reduces exposure to defects/advisories that may surface in the JDT-based code generation path. Keeping test dependencies current keeps the CVE/advisory surface of the build itself minimal and avoids drift from upstream Dependabot cadence.
Affected files
core/pom.xml
processor/pom.xml
Proposed remediation
Bump the outdated versions: Roaster to 2.31.1.Final (runtime), jackson-databind to 2.22.1 (test), and JUnit Jupiter to 6.1.2 (test). Validate with mvn clean verify. No known CVE affects the currently pinned versions; the bumps are hygiene/patch updates, the meaningful one being the shipped Roaster runtime dependency.
Problem
The
coreandprocessormodule POMs pin several dependency versions that have newer releases available. Most notably the only shipped runtime dependency with an available update is JBoss Roaster. Amvn versions:display-dependency-updatesaudit reports:org.jboss.forge.roaster:roaster-api/roaster-jdtcom.fasterxml.jackson.core:jackson-databindorg.junit.jupiter:junit-jupiter-*commons-lang3(3.20.0),commons-collections4(4.5.0),auto-service(1.1.1) andcompile-testing(0.23.0) are already current.Why it matters (high-security / high-reliability use)
For a library consumed as a compile-time dependency, keeping the shipped runtime dependency (Roaster) on the latest patch reduces exposure to defects/advisories that may surface in the JDT-based code generation path. Keeping test dependencies current keeps the CVE/advisory surface of the build itself minimal and avoids drift from upstream Dependabot cadence.
Affected files
core/pom.xmlprocessor/pom.xmlProposed remediation
Bump the outdated versions: Roaster to
2.31.1.Final(runtime),jackson-databindto2.22.1(test), and JUnit Jupiter to6.1.2(test). Validate withmvn clean verify. No known CVE affects the currently pinned versions; the bumps are hygiene/patch updates, the meaningful one being the shipped Roaster runtime dependency.