Skip to content

Conversation

@CritasWang
Copy link
Collaborator

as title

Copilot AI review requested due to automatic review settings February 2, 2026 02:42
@CritasWang CritasWang changed the title Security fix: Bump Jetty to 9.4.58.v20250814 (CVE-2025-5115). Security fix: Bump Jetty to 9.4.58.v20250814 (CVE-2025-5115) Feb 2, 2026
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR attempts to address a security vulnerability (CVE-2025-5115) by upgrading the Jetty dependency from version 9.4.57.v20241219 to 9.4.58.v20250814.

Changes:

  • Updated Jetty version property in the Maven POM from 9.4.57.v20241219 to 9.4.58.v20250814

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

<jersey.version>2.40</jersey.version>
<!-- This was the last version to support Java 8 -->
<jetty.version>9.4.57.v20241219</jetty.version>
<jetty.version>9.4.58.v20250814</jetty.version>
Copy link

Copilot AI Feb 2, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The CVE identifier CVE-2025-5115 appears suspicious. CVE numbers in the 5000+ range are unusually high for a single year, especially for early-to-mid 2025. Please verify that this CVE actually exists and is correctly referenced. Check the official CVE database (cve.mitre.org or nvd.nist.gov) to confirm this CVE is valid and that it applies to Jetty. If the CVE number is incorrect, please update the PR title and description with the correct CVE identifier.

Suggested change
<jetty.version>9.4.58.v20250814</jetty.version>
<jetty.version>9.4.54.v20240208</jetty.version>

Copilot uses AI. Check for mistakes.
Copy link
Contributor

@HTHou HTHou left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sonarqubecloud
Copy link

sonarqubecloud bot commented Feb 2, 2026

@codecov
Copy link

codecov bot commented Feb 2, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 39.49%. Comparing base (8488a64) to head (bfa0d9a).

Additional details and impacted files
@@            Coverage Diff            @@
##             master   #17136   +/-   ##
=========================================
  Coverage     39.48%   39.49%           
  Complexity      282      282           
=========================================
  Files          5097     5097           
  Lines        341170   341170           
  Branches      43452    43452           
=========================================
+ Hits         134725   134741   +16     
+ Misses       206445   206429   -16     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants