Skip to content

Remove redundant hidden configuration - #1189

Merged
rnc merged 1 commit into
project-ncl:mainfrom
rnc:BR1
Aug 26, 2026
Merged

Remove redundant hidden configuration#1189
rnc merged 1 commit into
project-ncl:mainfrom
rnc:BR1

Conversation

@rnc

@rnc rnc commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

No description provided.

@github-actions

Copy link
Copy Markdown
Contributor

Mend Scan Results

Status: ⚠️ Findings detected

⚠️ SCA findings detected

SCA scan output



Identified 124 dependencies

Detected 4 vulnerabilities (0 Critical, 2 High, 2 Medium, 0 Low)

+----------+----------------------------+----------------+--------------------------------------------------------------------------------------------+
| SEVERITY |          LIBRARY           |       ID       |                                          TOP FIX                                           |
+----------+----------------------------+----------------+--------------------------------------------------------------------------------------------+
| HIGH     | jsoup-1.22.1.jar           | CVE-2026-75140 | N/A                                                                                        |
+----------+----------------------------+----------------+--------------------------------------------------------------------------------------------+
| HIGH     | logback-classic-1.5.37.jar | CVE-2026-19880 | Upgrade to version ch.qos.logback:logback-classic:1.6.3                                    |
+----------+----------------------------+----------------+--------------------------------------------------------------------------------------------+
| MEDIUM   | ivy-2.5.3.jar              | CVE-2026-26032 | Upgrade to version org.apache.ivy:ivy:2.6.0, https://github.com/apache/ant-ivy.git -       |
|          |                            |                | rel/2.6.0                                                                                  |
+----------+----------------------------+----------------+--------------------------------------------------------------------------------------------+
| MEDIUM   | jsoup-1.22.1.jar           | CVE-2026-71497 | Upgrade to version org.jsoup:jsoup:1.23.1, https://github.com/jhy/jsoup.git - jsoup-1.23.1 |
+----------+----------------------------+----------------+--------------------------------------------------------------------------------------------+


Paths at risk

P = policy violation
MSC = malicious vulnerability
CRITICAL/HIGH/MEDIUM/LOW = vulnerability severity

pom-manipulation-cli-5.6-SNAPSHOT.jar
|-- logback-classic-1.5.37.jar [1 HIGH]
|-- ivy-2.5.3.jar [1 MEDIUM]
|-- atlas-identities-1.2.2.jar
	|-- logback-classic-1.5.37.jar [1 HIGH]
|-- org.eclipse.sisu.plexus-0.9.0.M4.jar
	|-- logback-classic-1.5.37.jar [1 HIGH]
|-- pom-manipulation-common-5.6-SNAPSHOT.jar
	|-- logback-classic-1.5.37.jar [1 HIGH]
	|-- galley-maven-1.22.jar
		|-- atlas-relationships-api-1.2.2.jar
			|-- logback-classic-1.5.37.jar [1 HIGH]
			|-- atlas-bindings-jackson-identities-1.2.2.jar
				|-- logback-classic-1.5.37.jar [1 HIGH]
|-- pom-manipulation-core-5.6-SNAPSHOT.jar
	|-- ivy-2.5.3.jar [1 MEDIUM]
	|-- groovy-3.0.25.jar
		|-- ivy-2.5.3.jar [1 MEDIUM]
|-- pom-manipulation-io-5.6-SNAPSHOT.jar
	|-- galley-core-1.22.jar
		|-- weft-1.26.jar
			|-- logback-classic-1.5.37.jar [1 HIGH]
	|-- galley-transport-httpclient-1.22.jar
		|-- jhttpc-1.17.jar
			|-- logback-classic-1.5.37.jar [1 HIGH]
		|-- jsoup-1.22.1.jar [1 HIGH, 1 MEDIUM]
pom-manipulation-core-5.6-SNAPSHOT.jar
|-- atlas-identities-1.2.2.jar
	|-- logback-classic-1.5.37.jar [1 HIGH]
|-- galley-maven-1.22.jar
	|-- atlas-relationships-api-1.2.2.jar
		|-- logback-classic-1.5.37.jar [1 HIGH]
		|-- atlas-bindings-jackson-identities-1.2.2.jar
			|-- logback-classic-1.5.37.jar [1 HIGH]
	|-- galley-core-1.22.jar
		|-- weft-1.26.jar
			|-- logback-classic-1.5.37.jar [1 HIGH]
|-- org.eclipse.sisu.plexus-0.9.0.M4.jar
	|-- logback-classic-1.5.37.jar [1 HIGH]
|-- pom-manipulation-common-5.6-SNAPSHOT.jar
	|-- logback-classic-1.5.37.jar [1 HIGH]
|-- pom-manipulation-io-5.6-SNAPSHOT.jar
	|-- galley-transport-httpclient-1.22.jar
		|-- jhttpc-1.17.jar
			|-- logback-classic-1.5.37.jar [1 HIGH]
		|-- jsoup-1.22.1.jar [1 HIGH, 1 MEDIUM]
pom-manipulation-coverage-5.6-SNAPSHOT.pom
|-- pom-manipulation-cli-5.6-SNAPSHOT.jar
	|-- logback-classic-1.5.37.jar [1 HIGH]
	|-- ivy-2.5.3.jar [1 MEDIUM]
	|-- org.eclipse.sisu.plexus-0.9.0.M4.jar
		|-- logback-classic-1.5.37.jar [1 HIGH]
		|-- org.eclipse.sisu.inject-0.9.0.M4.jar
			|-- logback-classic-1.5.37.jar [1 HIGH]
|-- pom-manipulation-common-5.6-SNAPSHOT.jar
	|-- logback-classic-1.5.37.jar [1 HIGH]
	|-- galley-maven-1.22.jar
		|-- atlas-relationships-api-1.2.2.jar
			|-- logback-classic-1.5.37.jar [1 HIGH]
			|-- atlas-bindings-jackson-identities-1.2.2.jar
				|-- logback-classic-1.5.37.jar [1 HIGH]
|-- pom-manipulation-core-5.6-SNAPSHOT.jar
	|-- ivy-2.5.3.jar [1 MEDIUM]
|-- pom-manipulation-ext-5.6-SNAPSHOT.jar
	|-- ivy-2.5.3.jar [1 MEDIUM]
	|-- atlas-identities-1.2.2.jar
		|-- logback-classic-1.5.37.jar [1 HIGH]
|-- pom-manipulation-integration-test-5.6-SNAPSHOT.jar
	|-- logback-classic-1.5.37.jar [1 HIGH]
	|-- groovy-3.0.25.jar
		|-- ivy-2.5.3.jar [1 MEDIUM]
	|-- pom-manipulation-cli-5.6-SNAPSHOT-minimal.jar
		|-- logback-classic-1.5.37.jar [1 HIGH]
		|-- ivy-2.5.3.jar [1 MEDIUM]
|-- pom-manipulation-io-5.6-SNAPSHOT.jar
	|-- galley-core-1.22.jar
		|-- weft-1.26.jar
			|-- logback-classic-1.5.37.jar [1 HIGH]
	|-- galley-transport-httpclient-1.22.jar
		|-- jhttpc-1.17.jar
			|-- logback-classic-1.5.37.jar [1 HIGH]
		|-- jsoup-1.22.1.jar [1 HIGH, 1 MEDIUM]
pom-manipulation-ext-5.6-SNAPSHOT.jar
|-- ivy-2.5.3.jar [1 MEDIUM]
|-- groovy-3.0.25.jar
	|-- ivy-2.5.3.jar [1 MEDIUM]
|-- atlas-identities-1.2.2.jar
	|-- logback-classic-1.5.37.jar [1 HIGH]
|-- galley-core-1.22.jar
	|-- weft-1.26.jar
		|-- logback-classic-1.5.37.jar [1 HIGH]
|-- galley-maven-1.22.jar
	|-- atlas-relationships-api-1.2.2.jar
		|-- logback-classic-1.5.37.jar [1 HIGH]
		|-- atlas-bindings-jackson-identities-1.2.2.jar
			|-- logback-classic-1.5.37.jar [1 HIGH]
|-- galley-transport-httpclient-1.22.jar
	|-- jhttpc-1.17.jar
		|-- logback-classic-1.5.37.jar [1 HIGH]
	|-- jsoup-1.22.1.jar [1 HIGH, 1 MEDIUM]
|-- org.eclipse.sisu.plexus-0.9.0.M4.jar
	|-- logback-classic-1.5.37.jar [1 HIGH]
|-- pom-manipulation-common-5.6-SNAPSHOT.jar
	|-- logback-classic-1.5.37.jar [1 HIGH]
|-- pom-manipulation-core-5.6-SNAPSHOT.jar
	|-- ivy-2.5.3.jar [1 MEDIUM]
pom-manipulation-integration-test-5.6-SNAPSHOT.jar
|-- logback-classic-1.5.37.jar [1 HIGH]
|-- groovy-3.0.25.jar
	|-- ivy-2.5.3.jar [1 MEDIUM]
|-- pom-manipulation-cli-5.6-SNAPSHOT-minimal.jar
	|-- logback-classic-1.5.37.jar [1 HIGH]
	|-- ivy-2.5.3.jar [1 MEDIUM]
|-- pom-manipulation-common-5.6-SNAPSHOT.jar
	|-- logback-classic-1.5.37.jar [1 HIGH]
	|-- galley-maven-1.22.jar
		|-- atlas-relationships-api-1.2.2.jar
			|-- logback-classic-1.5.37.jar [1 HIGH]
			|-- atlas-bindings-jackson-identities-1.2.2.jar
				|-- logback-classic-1.5.37.jar [1 HIGH]
|-- pom-manipulation-core-5.6-SNAPSHOT.jar
	|-- ivy-2.5.3.jar [1 MEDIUM]
	|-- org.eclipse.sisu.plexus-0.9.0.M4.jar
		|-- logback-classic-1.5.37.jar [1 HIGH]
|-- pom-manipulation-io-5.6-SNAPSHOT.jar
	|-- maven-release-manager-3.3.1.jar
		|-- org.eclipse.sisu.inject-0.9.0.M4.jar
			|-- logback-classic-1.5.37.jar [1 HIGH]
	|-- atlas-identities-1.2.2.jar
		|-- logback-classic-1.5.37.jar [1 HIGH]
	|-- galley-core-1.22.jar
		|-- weft-1.26.jar
			|-- logback-classic-1.5.37.jar [1 HIGH]
	|-- galley-transport-httpclient-1.22.jar
		|-- jhttpc-1.17.jar
			|-- logback-classic-1.5.37.jar [1 HIGH]
		|-- jsoup-1.22.1.jar [1 HIGH, 1 MEDIUM]
pom-manipulation-io-5.6-SNAPSHOT.jar
|-- atlas-identities-1.2.2.jar
	|-- logback-classic-1.5.37.jar [1 HIGH]
|-- galley-core-1.22.jar
	|-- weft-1.26.jar
		|-- logback-classic-1.5.37.jar [1 HIGH]
|-- galley-maven-1.22.jar
	|-- atlas-relationships-api-1.2.2.jar
		|-- logback-classic-1.5.37.jar [1 HIGH]
		|-- atlas-bindings-jackson-identities-1.2.2.jar
			|-- logback-classic-1.5.37.jar [1 HIGH]
|-- galley-transport-httpclient-1.22.jar
	|-- jhttpc-1.17.jar
		|-- logback-classic-1.5.37.jar [1 HIGH]
	|-- jsoup-1.22.1.jar [1 HIGH, 1 MEDIUM]
|-- pom-manipulation-common-5.6-SNAPSHOT.jar
	|-- logback-classic-1.5.37.jar [1 HIGH]


No Policy violations were detected

Project 'pom-manipulation-ext' was updated, for more information, visit the Mend platform: https://ibmets.whitesourcesoftware.com/app/orgs/Enterprise%20Applications/applications/summary?project=075c6d5a-0def-4e8c-a0ee-0cec98171bbc
Or the Core UI: https://ibmets.whitesourcesoftware.com/Wss/WSS.html#!project;token=72296f38fc25458c9def76cf0806c3197bf21c40d1db4af89c6e80faca013636

Mend AI scan succeeded.

Support Token: 0f8cb3003b137485c984e45f912bad0441787678953052
SAST scan output
*no findings*

Full logs and artifacts

@rnc
rnc merged commit 9b16a2e into project-ncl:main Aug 26, 2026
12 checks passed
@rnc
rnc deleted the BR1 branch August 26, 2026 07:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant