Skip to content

Conversation

@pull
Copy link

@pull pull bot commented Jan 30, 2026

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

devin-ai-integration bot and others added 4 commits January 30, 2026 06:05
…ilities (#11982)

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Niels Swimberghe <3382717+Swimburger@users.noreply.github.com>
Co-authored-by: fern-support <fern-support@users.noreply.github.com>
* [Grype Scan][java-sdk] Scaffold PR for 29 vulnerabilities

* fix: address java-sdk container security vulnerabilities

- Update Node.js from 23.11.1 to 22.22.0 (fixes CVE-2025-59465, CVE-2025-55131, CVE-2025-55130, CVE-2026-21637, CVE-2025-59466, CVE-2025-55132)
- Update tar from 7.5.3 to 7.5.7 (fixes GHSA-34x7-hfp2-rc4v, GHSA-r6q2-hw4h-h46w)
- Add openssl/libssl3 upgrade (fixes CVE-2025-15467, CVE-2026-22796, CVE-2026-22795, CVE-2025-69420, CVE-2025-69419, CVE-2025-68160, CVE-2025-69421, CVE-2025-69418)
- Update logback-classic from 1.3.16 to 1.5.25 (fixes GHSA-qqpg-mvqg-649v)
- Update slf4j-api from 1.7.36 to 2.0.16 (required for logback 1.5.x compatibility)
- Delete scaffold file

Note: OpenJDK CVEs (CVE-2026-21945, CVE-2026-21932, CVE-2026-21925, CVE-2026-21933) require 11.0.30 which is not yet available
Co-Authored-By: unknown <>

* fix: upgrade Node.js to 24.13.0 instead of downgrading to 22.22.0

Per review feedback, upgrading to Node.js 24.13.0 rather than downgrading to 22.22.0 LTS.
Node.js 23.x does not have security patches available as it's an odd-numbered release
that stopped receiving updates when Node.js 24 was released.

Co-Authored-By: unknown <>

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: David Konigsberg <72822263+davidkonigsberg@users.noreply.github.com>
…1948)

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: paarth@buildwithfern.com <paarth@buildwithfern.com>
@pull pull bot locked and limited conversation to collaborators Jan 30, 2026
@pull pull bot added the ⤵️ pull label Jan 30, 2026
@pull pull bot merged commit c23178c into code:main Jan 30, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant