From 402f82f48f817f46b559332e1d02cef2c7a14dc4 Mon Sep 17 00:00:00 2001 From: Eduard Tita Date: Thu, 10 Sep 2026 13:29:05 -0400 Subject: [PATCH] fix: pin com.github.luben:zstd-jni to 1.5.7-16 to resolve IQ violations Scan: bd76f9750eda4967be361a9e7ccbe7aa Component: com.github.luben:zstd-jni:1.5.7-4 -> 1.5.7-16 Dependency type: transitive Strategy: gradle-constraint Path: insight-scanner-archive:3.0.65-01 -> insight-scanner-container-image:3.0.65-01 -> zstd-jni:1.5.7-4 No direct-dependency upgrade path exists: insight-scanner-archive is a private Sonatype internal artifact not indexed by Sonatype Guide. Checked its source repo locally - both the latest released version (3.0.65-01) and the unreleased HEAD (3.0.66-SNAPSHOT) still pin zstd-jni at 1.5.7-4 in insight-scanner-container-image's pom.xml. Pinning the transitive version via Gradle constraints (existing pattern in this file) until insight-scanner ships a release with the bump upstream. Resolved violations: - Security-High (threat level 9): Found security vulnerability CVE-2026-87795 with severity >= 7 (severity = 8.2) - Security-High (threat level 9): Found security vulnerability CVE-2026-87823 with severity >= 7 (severity = 8.8) --- build.gradle | 3 +++ 1 file changed, 3 insertions(+) diff --git a/build.gradle b/build.gradle index e095894..824dfaf 100644 --- a/build.gradle +++ b/build.gradle @@ -110,6 +110,9 @@ dependencies { implementation('org.apache.logging.log4j:log4j-api:2.26.1') { because('Temporarily pinning version to avoid sonatype-2026-006746') } + implementation('com.github.luben:zstd-jni:1.5.7-16') { + because('Pinning version to avoid CVE-2026-87795 and CVE-2026-87823 (transitive via insight-scanner-archive)') + } } testImplementation gradleTestKit()