[Backport 2.19] Bump logback core to 1.15.20 #1976
Open
Mend for GitHub.com / WhiteSource Security Check
failed
Mar 5, 2026 in 2m 6s
Security Report
1 new vulnerabilities were introduced in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|---|
CVE-2026-1225Path to dependency file: /build.gradle Path to vulnerable library: /tmp/containerbase/cache/.gradle/caches/modules-2/files-2.1/ch.qos.logback/logback-core/1.5.20/c5e87126a18d729240c683db179a9387b2daa632/logback-core-1.5.20.jar Dependency Hierarchy: -> ktlint-0.47.1.jar (Root Library) -> logback-classic-1.5.20.jar -> ❌ logback-core-1.5.20.jar (Vulnerable Library) |
5.0 | Transitive logback-core-1.5.20.jar |
ktlint-0.47.1.jar | Transitive https://github.com/qos-ch/logback.git - v_1.5.25 |
None |
Base branch total remaining vulnerabilities: 0
Base branch commit: d3ad645c25a53d071283f4d31fc4abdfb0426e31
Total libraries scanned: 156
Scan token: a91fcb52e470422eb3eca94e593083ca
Loading