Skip to content

Conversation

@mcollovati
Copy link
Contributor

Prevents potential issues with Maven versions >= 3.9.12 if a Java version newer than the supported one is used to package the Maven plugin.

Prevents potential issues with Maven versions >= 3.9.12 if a Java version
newer than the supported one is used to package the Maven plugin.
@mcollovati mcollovati changed the title fix: Set required Java and Maven versions in vaadin-maven-plugin fix: Set required Java and Maven versions in vaadin-maven-plugin (23.7) Feb 9, 2026
@github-actions
Copy link

github-actions bot commented Feb 9, 2026

Dependencies Report

  • 🟠 Known Vulnerabilities:

  • 🚫 Vulnerabilities:

    • Vulnerabilities in: pkg:maven/com.fasterxml.jackson.core/jackson-core@2.14.2 [CVE-2025-52999] (osv-bomber,osv-scan)
      ·
      • Vulnerabilities in: pkg:maven/com.nimbusds/nimbus-jose-jwt@9.37.3 [CVE-2025-53864] (osv-bomber,osv-scan)
        ·
      • Vulnerabilities in: pkg:maven/org.apache.poi/poi-ooxml@5.2.3 [CVE-2025-31672] (osv-bomber,osv-scan)
        ·
      • Vulnerabilities in: pkg:maven/org.springframework/spring-websocket@5.3.32 [CVE-2025-41254] (osv-bomber,osv-scan)
        ·
      • Vulnerabilities in: pkg:maven/org.springframework/spring-web@5.3.32 [CVE-2024-38809, CVE-2024-22262, CVE-2024-38820, CVE-2016-1000027, CVE-2024-22259, CVE-2024-38808] (osv-bomber,osv-scan,owasp)
        ·
        · cpe:2.3:a:vmware:spring_framework::::::::
        · cpe:2.3:a:netapp:active_iq_unified_manager:-:::::linux::
        · cpe:2.3:a:netapp:active_iq_unified_manager:-:::::vmware_vsphere::
        · cpe:2.3:a:netapp:active_iq_unified_manager:-:::::windows::
        · cpe:2.3:a:netapp:oncommand_insight:-:::::::*
      • Vulnerabilities in: pkg:maven/org.springframework/spring-core@5.3.32 [CVE-2025-41249, CVE-2024-22259, CVE-2024-38820, CVE-2024-38808] (osv-bomber,osv-scan,owasp)
        ·
        · cpe:2.3:a:netapp:active_iq_unified_manager:-:::::linux::
        · cpe:2.3:a:netapp:active_iq_unified_manager:-:::::vmware_vsphere::
        · cpe:2.3:a:netapp:active_iq_unified_manager:-:::::windows::
        · cpe:2.3:a:vmware:spring_framework::::::::
        · cpe:2.3:a:netapp:oncommand_insight:-:::::::*
      • Vulnerabilities in: pkg:maven/org.springframework/spring-webmvc@5.3.32 [CVE-2024-38816, CVE-2024-38819, CVE-2025-41242, CVE-2024-38828] (osv-bomber,osv-scan)
        ·
      • Vulnerabilities in: pkg:maven/org.springframework/spring-context@5.3.32 [CVE-2024-38820, CVE-2025-22233] (osv-bomber,osv-scan)
        ·
      • Vulnerabilities in: pkg:maven/org.springframework/spring-expression@5.3.32 [CVE-2024-38808] (osv-bomber,osv-scan)
        ·
      • Vulnerabilities in: pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.104 [CVE-2025-49124, CVE-2025-48989, CVE-2025-46701, CVE-2025-48988, CVE-2025-61795, CVE-2025-55754, CVE-2025-49125, CVE-2025-55752, BIT-tomcat-2025-49124, BIT-tomcat-2025-48989, BIT-tomcat-2025-46701, BIT-tomcat-2025-48988, BIT-tomcat-2025-61795, BIT-tomcat-2025-55754, BIT-tomcat-2025-49125, BIT-tomcat-2025-55752, CVE-2025-52434, CVE-2025-52520, CVE-2025-53506, CVE-2025-55668] (osv-bomber,osv-scan,owasp)
        · cpe:2.3:a:apache:tomcat::::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone1::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone10::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone11::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone12::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone13::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone14::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone15::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone16::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone17::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone18::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone19::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone2::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone20::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone21::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone22::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone23::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone24::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone25::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone26::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone27::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone3::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone4::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone5::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone6::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone7::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone8::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:milestone9::::::
        · cpe:2.3:a:apache:tomcat:9.0.0:-::::::
        ·
      • Vulnerabilities in: pkg:maven/ch.qos.logback/logback-core@1.2.13 [CVE-2025-11226, CVE-2024-12801, CVE-2024-12798, CVE-2026-1225] (osv-bomber,osv-scan)
        ·
      • Vulnerabilities in: pkg:maven/org.springframework.boot/spring-boot@2.7.18 [CVE-2025-22235] (osv-bomber,osv-scan)
        ·
      • Vulnerabilities in: pkg:npm/vite@3.2.11#packages/vite [CVE-2025-32395, CVE-2025-31125, CVE-2025-46565, CVE-2025-62522, CVE-2025-58751, CVE-2025-58752, CVE-2025-24010, CVE-2025-30208, CVE-2025-31486] (osv-bomber)
        ·
      • Vulnerabilities in: pkg:npm/path-to-regexp@2.4.0 [CVE-2024-45296] (osv-bomber,oss-bomber,osv-scan)
        ·
      • Vulnerabilities in: pkg:npm/esbuild@0.15.18 [GHSA-67mh-4wv8-2f99] (osv-bomber)
        ·
      • Vulnerabilities in: pkg:npm/libxmljs2@0.37.0 [CVE-2024-34393, CVE-2024-34394] (oss-bomber)
        ·
      • Vulnerabilities in: pkg:maven/org.apache.tomcat/tomcat@9.0.104 [BIT-tomcat-2025-49124, CVE-2025-49124, BIT-tomcat-2025-61795, CVE-2025-61795, BIT-tomcat-2025-55754, CVE-2025-55754, BIT-tomcat-2025-55752, CVE-2025-55752] (osv-scan)
        ·
      • Vulnerabilities in: pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.104 [BIT-tomcat-2025-49124, CVE-2025-49124, BIT-tomcat-2025-46701, CVE-2025-46701, BIT-tomcat-2025-48988, CVE-2025-48988, BIT-tomcat-2025-61795, CVE-2025-61795, BIT-tomcat-2025-55754, CVE-2025-55754, BIT-tomcat-2025-49125, CVE-2025-49125, BIT-tomcat-2025-55752, CVE-2025-55752] (osv-scan)
        ·
      • Vulnerabilities in: pkg:maven/org.apache.tomcat/tomcat-coyote@9.0.104 [BIT-tomcat-2025-48989, CVE-2025-48989] (osv-scan)
        ·
      • Vulnerabilities in: pkg:maven/org.springframework/spring-webflux@5.3.32 [CVE-2024-38816, CVE-2024-38819] (osv-scan)
        ·
      • Vulnerabilities in: pkg:npm/vite@3.2.11 [CVE-2025-32395, CVE-2025-31125, CVE-2025-46565, CVE-2025-62522, CVE-2025-58751, CVE-2025-58752, CVE-2025-24010, CVE-2025-30208, CVE-2025-31486] (osv-scan)
        ·
      • Vulnerabilities in: pkg:maven/org.apache.poi/poi@5.2.3 [CVE-2025-31672] (owasp)
        · cpe:2.3:a:apache:poi::::::::
        · cpe:2.3:a:netapp:active_iq_unified_manager:-:::::linux::
        · cpe:2.3:a:netapp:active_iq_unified_manager:-:::::vmware_vsphere::
        · cpe:2.3:a:netapp:active_iq_unified_manager:-:::::windows::
  • 🟠 Changes in 23.7-SNAPSHOT since V23.7.0-beta1

    • 26 packages modified (26 external, 0 vaadin)
    • 779 packages same (603 external, 176 vaadin)

[Click for more Details]

@ZheSun88 ZheSun88 merged commit fb499f7 into 23.7 Feb 9, 2026
3 of 5 checks passed
@ZheSun88 ZheSun88 deleted the fix/set-required-java-version-for-maven-plugin-23.7 branch February 9, 2026 13:25
vaadin-bot pushed a commit that referenced this pull request Feb 9, 2026
Prevents potential issues with Maven versions >= 3.9.12 if a Java version
newer than the supported one is used to package the Maven plugin.
ZheSun88 pushed a commit that referenced this pull request Feb 10, 2026
…) (#8504)

Prevents potential issues with Maven versions >= 3.9.12 if a Java version
newer than the supported one is used to package the Maven plugin.

Co-authored-by: Marco Collovati <marco@vaadin.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants