Skip to content

Update dependency org.apache.calcite:calcite-core to v1.37.0

3fe4db4
Select commit
Loading
Failed to load commit list.
Open

Update dependency org.apache.calcite:calcite-core to v1.37.0 #2

Update dependency org.apache.calcite:calcite-core to v1.37.0
3fe4db4
Select commit
Loading
Failed to load commit list.
Dev - Mend for GitHub.com / Mend Security Check failed Feb 25, 2026 in 53m 26s

Security Report

You have successfully remediated 27 vulnerabilities, but introduced 3 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2024-7254

Path to dependency file: /calcite-tutorial-4-validator/validator-1-calcite-validator/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.21.9/protobuf-java-3.21.9.jar,/home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.21.9/protobuf-java-3.21.9.jar,/home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.21.9/protobuf-java-3.21.9.jar,/home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.21.9/protobuf-java-3.21.9.jar,/home/wss-scanner/.m2/repository/com/google/protobuf/protobuf-java/3.21.9/protobuf-java-3.21.9.jar

Dependency Hierarchy:

-> calcite-core-1.37.0.jar (Root Library)

   -> calcite-linq4j-1.37.0.jar

     -> avatica-core-1.25.0.jar

       -> ❌ protobuf-java-3.21.9.jar (Vulnerable Library)

High 7.5 Transitive protobuf-java-3.21.9.jar calcite-core-1.37.0.jar Transitive com.google.protobuf:protobuf-javalite:3.25.5,com.google.protobuf:protobuf-kotlin:4.28.2,com.google.protobuf:protobuf-kotlin-lite:4.28.2,com.google.protobuf:protobuf-java:4.27.5,com.google.protobuf:protobuf-kotlin-lite:4.27.5,com.google.protobuf:protobuf-javalite:4.28.2,com.google.protobuf:protobuf-kotlin:4.27.5,com.google.protobuf:protobuf-java:4.28.2,com.google.protobuf:protobuf-javalite:4.27.5,com.google.protobuf:protobuf-javalite:4.28.2,com.google.protobuf:protobuf-java:4.28.2,com.google.protobuf:protobuf-javalite:4.27.5,com.google.protobuf:protobuf-java:3.25.5,com.google.protobuf:protobuf-java:4.27.5,com.google.protobuf:protobuf-kotlin:4.28.2,google-protobuf - 4.27.5,com.google.protobuf:protobuf-kotlin:4.27.5,com.google.protobuf:protobuf-kotlin-lite:4.27.5,com.google.protobuf:protobuf-kotlin:3.25.5,google-protobuf - 4.28.2,com.google.protobuf:protobuf-kotlin-lite:4.28.2,google-protobuf - 3.25.5,com.google.protobuf:protobuf-kotlin-lite:3.25.5 None

Reachable

CVE-2024-57699

Path to dependency file: /calcite-tutorial-4-validator/validator-1-calcite-validator/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/net/minidev/json-smart/2.5.0/json-smart-2.5.0.jar,/home/wss-scanner/.m2/repository/net/minidev/json-smart/2.5.0/json-smart-2.5.0.jar,/home/wss-scanner/.m2/repository/net/minidev/json-smart/2.5.0/json-smart-2.5.0.jar,/home/wss-scanner/.m2/repository/net/minidev/json-smart/2.5.0/json-smart-2.5.0.jar,/home/wss-scanner/.m2/repository/net/minidev/json-smart/2.5.0/json-smart-2.5.0.jar,/home/wss-scanner/.m2/repository/net/minidev/json-smart/2.5.0/json-smart-2.5.0.jar

Dependency Hierarchy:

-> calcite-core-1.37.0.jar (Root Library)

   -> json-path-2.9.0.jar

     -> ❌ json-smart-2.5.0.jar (Vulnerable Library)

High 7.5 Transitive json-smart-2.5.0.jar calcite-core-1.37.0.jar Transitive 2.5.2 None

Reachable

CVE-2025-48924

Path to dependency file: /calcite-tutorial-4-validator/validator-1-calcite-validator/pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/apache/commons/commons-lang3/3.13.0/commons-lang3-3.13.0.jar,/home/wss-scanner/.m2/repository/org/apache/commons/commons-lang3/3.13.0/commons-lang3-3.13.0.jar,/home/wss-scanner/.m2/repository/org/apache/commons/commons-lang3/3.13.0/commons-lang3-3.13.0.jar,/home/wss-scanner/.m2/repository/org/apache/commons/commons-lang3/3.13.0/commons-lang3-3.13.0.jar,/home/wss-scanner/.m2/repository/org/apache/commons/commons-lang3/3.13.0/commons-lang3-3.13.0.jar,/home/wss-scanner/.m2/repository/org/apache/commons/commons-lang3/3.13.0/commons-lang3-3.13.0.jar

Dependency Hierarchy:

-> calcite-core-1.37.0.jar (Root Library)

   -> uzaygezen-core-0.2.jar

     -> ❌ commons-lang3-3.13.0.jar (Vulnerable Library)

Medium 5.3 Transitive commons-lang3-3.13.0.jar calcite-core-1.37.0.jar Transitive 3.18.0 None

Reachable

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2021-44832 log4j-core-2.13.2.jar
CVE-2021-4104 log4j-1.2.17.jar
WS-2019-0379 commons-codec-1.12.jar
CVE-2023-1370 json-smart-2.3.jar
CVE-2020-8908 guava-23.0.jar
CVE-2025-48924 commons-lang3-3.8.jar
CVE-2017-18640 snakeyaml-1.24.jar
CVE-2023-26464 log4j-1.2.17.jar
CVE-2025-52999 jackson-core-2.10.0.jar
CVE-2022-38751 snakeyaml-1.24.jar
CVE-2022-41854 snakeyaml-1.24.jar
CVE-2022-38749 snakeyaml-1.24.jar
CVE-2022-42004 jackson-databind-2.10.0.jar
CVE-2022-38750 snakeyaml-1.24.jar
CVE-2020-13956 httpclient-4.5.9.jar
CVE-2022-38752 snakeyaml-1.24.jar
CVE-2021-27568 json-smart-2.3.jar
CVE-2022-36364 avatica-core-1.17.0.jar
CVE-2021-29425 commons-io-2.4.jar
CVE-2024-47554 commons-io-2.4.jar
CVE-2023-51074 json-path-2.4.0.jar
CVE-2020-9488 log4j-1.2.17.jar
CVE-2022-39135 calcite-core-1.26.0.jar
WS-2020-0287 commons-dbcp2-2.6.0.jar
CVE-2019-17571 log4j-1.2.17.jar
CVE-2020-9493 log4j-1.2.17.jar
CVE-2022-42003 jackson-databind-2.10.0.jar

Base branch total remaining vulnerabilities: 38
Base branch commit: null


Total libraries scanned: 54

Scan token: b0e43ed0fc2e41968620ab5c0c916748