build: modernize Maven deps & multi-version packaging - #24
Open
shiftySenpai wants to merge 6 commits into
Open
Conversation
Extract buildHecEnvelope() helper in SingleSplunkConnection using gson
(already a shared-mc dependency) instead of the unmaintained json-simple
1.1 library. Wire format is unchanged: {"event": <message>}. Adds unit
tests covering basic wrapping and quote escaping, and removes the
json-simple dependency from shared-mc/pom.xml and the parent pom's
dependencyManagement.
…'d deps Adds per-platform MC-version Maven profiles (spigot: 1.21.1 default plus 1.20.1/1.20.4/1.20.6), a shade-plugin build producing logtosplunk-<mc.version>-<loader>-<loader.version>.jar per module, and marks server-provided deps (log4j, spigot-api) as provided scope so they aren't shaded into the plugin jar. Pins kotlin-stdlib to 2.0.21 to clear CVE-2026-53914 pulled in transitively via splunk-library-javalogging -> okhttp3 -> kotlin-stdlib:1.6.20. Tunes the OWASP dependency-check plugin to skip provided-scope CVEs (server operator's responsibility) and not fail on Sonatype OSS Index 401s (paid-only), while still enforcing the CVSS 7.0 gate.
This was referenced Aug 17, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Split out of #23 (build/dependency slice). No functional logging/feature changes.
logtosplunk-<mc.version>-<loader>-<loader.version>.jar), pins a transitively-pulled CVE'dkotlin-stdlib.Rebased onto current
develop(past the recentspigot/pom.xmlcraftbukkit 26.2 bump) — the old hardcoded spigot-api/bukkit dependency block that commit touched is fully replaced here by the new profile-based system, so that block is removed rather than merged. Worth a maintainer sanity-check that the default profile'sspigot.api.version(currently MC-version-keyed, e.g.1.21.1-R0.1-SNAPSHOT) still resolves given the newer26.2-R0.1-<timestamp>coordinates upstream is now publishing under.Test plan
mvn clean package(not verified in this environment — no local Maven install; please build-check before merging)Part of the #23 split (see that PR for full context/links to the other 4 pieces).