Skip to content

[RUN-4933] Bump rundeck-core to 6.2.0-20260908 (CVE-2026-19032) - #163

Open
fdevans wants to merge 1 commit into
mainfrom
security/CVE-2026-19032-jackson
Open

[RUN-4933] Bump rundeck-core to 6.2.0-20260908 (CVE-2026-19032)#163
fdevans wants to merge 1 commit into
mainfrom
security/CVE-2026-19032-jackson

Conversation

@fdevans

@fdevans fdevans commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

What

Bumps rundeck-core from 6.1.0-20260803 to 6.2.0-20260908.

Why

CVE-2026-19032: 6.1.0-20260803 pulls in a vulnerable transitive
Jackson version. 6.2.0-20260908 includes the fix.

Note

6.2.0-20260908 was published today. If the CI build here fails to
resolve it, that's expected propagation lag on the Sonatype snapshots
feed, not a real problem with this change - rerun the build once it's
synced.

rundeck-core 6.1.0-20260803 pulls in a vulnerable transitive Jackson
version (CVE-2026-19032). 6.2.0-20260908 includes the fix.
@fdevans
fdevans requested review from a team and a lite review from Copilot September 8, 2026 22:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The new rundeck-core version and its transitive Jackson CVE fix should be verified as resolvable and effective (or made deterministic via an explicit override) before merging.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This PR updates the build’s Rundeck dependency to pick up a security fix (CVE-2026-19032) by bumping org.rundeck:rundeck-core to a newer dated build.

Changes:

  • Bump rundeck-core from 6.1.0-20260803 to 6.2.0-20260908 via the Gradle version catalog.
File summaries
File Description
gradle/libs.versions.toml Updates the pinned rundeck-core version used for compileOnly/tests to the new security-fix build.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread gradle/libs.versions.toml
expectit = "0.9.0"
commonsIo = "2.22.0"
rundeckCore = "6.1.0-20260803"
rundeckCore = "6.2.0-20260908"
@fdevans fdevans changed the title Bump rundeck-core to 6.2.0-20260908 (CVE-2026-19032) [RUN-4933] Bump rundeck-core to 6.2.0-20260908 (CVE-2026-19032) Sep 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants