Skip to content

Audit and refresh core/processor dependency versions #174

Description

@devin-ai-integration

Problem

The core and processor module POMs pin several dependency versions that have newer releases available. Most notably the only shipped runtime dependency with an available update is JBoss Roaster. A mvn versions:display-dependency-updates audit reports:

Dependency Scope Current Available
org.jboss.forge.roaster:roaster-api / roaster-jdt runtime (processor) 2.31.0.Final 2.31.1.Final
com.fasterxml.jackson.core:jackson-databind test (processor) 2.21.1 2.22.1
org.junit.jupiter:junit-jupiter-* test (core, processor) 6.0.3 6.1.2

commons-lang3 (3.20.0), commons-collections4 (4.5.0), auto-service (1.1.1) and compile-testing (0.23.0) are already current.

Why it matters (high-security / high-reliability use)

For a library consumed as a compile-time dependency, keeping the shipped runtime dependency (Roaster) on the latest patch reduces exposure to defects/advisories that may surface in the JDT-based code generation path. Keeping test dependencies current keeps the CVE/advisory surface of the build itself minimal and avoids drift from upstream Dependabot cadence.

Affected files

  • core/pom.xml
  • processor/pom.xml

Proposed remediation

Bump the outdated versions: Roaster to 2.31.1.Final (runtime), jackson-databind to 2.22.1 (test), and JUnit Jupiter to 6.1.2 (test). Validate with mvn clean verify. No known CVE affects the currently pinned versions; the bumps are hygiene/patch updates, the meaningful one being the shipped Roaster runtime dependency.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions