From 60f1c0c872163b3de7c5088b5fed6cdcc02a9919 Mon Sep 17 00:00:00 2001 From: "lineaje-autofix[bot]" Date: Wed, 14 Jan 2026 19:19:59 +0000 Subject: [PATCH 1/4] [lineaje] Update org.apache.xmlgraphics:batik-bridge:1.13 to 1.17 Fixes CVEs - CVE-2022-38648,CVE-2022-42890,CVE-2022-44729 --- pom.xml | 373 ++++++++++++++++++++++++++++---------------------------- 1 file changed, 186 insertions(+), 187 deletions(-) diff --git a/pom.xml b/pom.xml index 7f8c9c7..5639fc4 100644 --- a/pom.xml +++ b/pom.xml @@ -1,187 +1,186 @@ - - 4.0.0 - - com.example - my-app - 1.0-SNAPSHOT - - - 1.8 - 1.8 - - - - - junit - junit - 4.12 - test - - - org.springframework - spring-core - 5.3.9 - - - com.fasterxml.jackson.core - jackson-databind - 2.12.3 - - - org.apache.commons - commons-lang3 - 3.12.0 - - - org.apache.logging.log4j - log4j-core - 2.14.1 - - - org.apache.logging.log4j - log4j-api - 2.14.1 - - - org.hibernate - hibernate-core - 5.4.32.Final - - - org.apache.httpcomponents - httpclient - 4.5.13 - - - org.apache.httpcomponents - httpcore - 4.4.14 - - - org.apache.poi - poi - 5.0.0 - - - org.apache.poi - poi-ooxml - 5.0.0 - - - org.apache.poi - poi-ooxml-schemas - 4.1.2 - - - org.apache.commons - commons-io - 2.8.0 - - - org.apache.commons - commons-collections4 - 4.4 - - - org.apache.commons - commons-math3 - 3.6.1 - - - org.apache.commons - commons-codec - 1.15 - - - org.apache.commons - commons-dbcp2 - 2.8.0 - - - org.apache.commons - commons-pool2 - 2.9.0 - - - org.apache.commons - commons-text - 1.9 - - - org.apache.commons - commons-validator - 1.7 - - - org.apache.commons - commons-jxpath - 1.3 - - - org.apache.commons - commons-beanutils - 1.9.4 - - - org.apache.commons - commons-digester3 - 3.3 - - - org.apache.commons - commons-configuration2 - 2.7 - - - org.apache.commons - commons-vfs2 - 2.8.0 - - - org.apache.commons - commons-compress - 1.21 - - - org.apache.commons - commons-exec - 1.3 - - - org.apache.commons - commons-net - 3.8.0 - - - org.apache.commons - commons-email - 1.5 - - - org.apache.commons - commons-jcs - 2.2 - - - org.apache.commons - commons-jexl3 - 3.1 - - - - - - - org.apache.maven.plugins - maven-compiler-plugin - 3.8.1 - - 1.8 - 1.8 - - - - - + + 4.0.0 + com.example + my-app + 1.0-SNAPSHOT + + 1.8 + 1.8 + + + + junit + junit + 4.12 + test + + + org.springframework + spring-core + 5.3.9 + + + com.fasterxml.jackson.core + jackson-databind + 2.12.3 + + + org.apache.commons + commons-lang3 + 3.12.0 + + + org.apache.logging.log4j + log4j-core + 2.14.1 + + + org.apache.logging.log4j + log4j-api + 2.14.1 + + + org.hibernate + hibernate-core + 5.4.32.Final + + + org.apache.httpcomponents + httpclient + 4.5.13 + + + org.apache.httpcomponents + httpcore + 4.4.14 + + + org.apache.poi + poi + 5.0.0 + + + org.apache.poi + poi-ooxml + 5.0.0 + + + org.apache.poi + poi-ooxml-schemas + 4.1.2 + + + org.apache.commons + commons-io + 2.8.0 + + + org.apache.commons + commons-collections4 + 4.4 + + + org.apache.commons + commons-math3 + 3.6.1 + + + org.apache.commons + commons-codec + 1.15 + + + org.apache.commons + commons-dbcp2 + 2.8.0 + + + org.apache.commons + commons-pool2 + 2.9.0 + + + org.apache.commons + commons-text + 1.9 + + + org.apache.commons + commons-validator + 1.7 + + + org.apache.commons + commons-jxpath + 1.3 + + + org.apache.commons + commons-beanutils + 1.9.4 + + + org.apache.commons + commons-digester3 + 3.3 + + + org.apache.commons + commons-configuration2 + 2.7 + + + org.apache.commons + commons-vfs2 + 2.8.0 + + + org.apache.commons + commons-compress + 1.21 + + + org.apache.commons + commons-exec + 1.3 + + + org.apache.commons + commons-net + 3.8.0 + + + org.apache.commons + commons-email + 1.5 + + + org.apache.commons + commons-jcs + 2.2 + + + org.apache.commons + commons-jexl3 + 3.1 + + + org.apache.xmlgraphics + batik-bridge:1.13 + 1.17 + + + + + + org.apache.maven.plugins + maven-compiler-plugin + 3.8.1 + + 1.8 + 1.8 + + + + + \ No newline at end of file From e93c2b06b38b246bcd8e719d222a893c4ff39c2d Mon Sep 17 00:00:00 2001 From: "lineaje-autofix[bot]" Date: Wed, 14 Jan 2026 19:21:10 +0000 Subject: [PATCH 2/4] [lineaje] Update org.apache.logging.log4j:log4j-core:2.14.1 to 2.25.3 Fixes CVEs - CVE-2021-44228,CVE-2021-44832,CVE-2021-45046,CVE-2021-45105,CVE-2025-68161,GHSA-vc5p-v9hr-52mj --- pom.xml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pom.xml b/pom.xml index 5639fc4..77d3ef8 100644 --- a/pom.xml +++ b/pom.xml @@ -169,6 +169,11 @@ batik-bridge:1.13 1.17 + + org.apache.logging.log4j + log4j-core:2.14.1 + 2.25.3 + From 4329b42cb3fcdf7cf0dfe04bd4c92a121581e55d Mon Sep 17 00:00:00 2001 From: "lineaje-autofix[bot]" Date: Wed, 14 Jan 2026 19:22:18 +0000 Subject: [PATCH 3/4] [lineaje] Update org.apache.xmlgraphics:batik-svgbrowser:1.13 to 1.14 Fixes CVEs - CVE-2020-11987 --- pom.xml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pom.xml b/pom.xml index 77d3ef8..35a04f1 100644 --- a/pom.xml +++ b/pom.xml @@ -174,6 +174,11 @@ log4j-core:2.14.1 2.25.3 + + org.apache.xmlgraphics + batik-svgbrowser:1.13 + 1.14 + From 566e23f94230244c2910602c0e4a91e8e3be022c Mon Sep 17 00:00:00 2001 From: "lineaje-autofix[bot]" Date: Wed, 14 Jan 2026 19:23:27 +0000 Subject: [PATCH 4/4] [lineaje] Update org.apache.xmlgraphics:batik-transcoder:1.13 to 1.17 Fixes CVEs - CVE-2022-44729 --- pom.xml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/pom.xml b/pom.xml index 35a04f1..9d792bd 100644 --- a/pom.xml +++ b/pom.xml @@ -179,6 +179,11 @@ batik-svgbrowser:1.13 1.14 + + org.apache.xmlgraphics + batik-transcoder:1.13 + 1.17 +