The GitHub Actions job "Vulnerability Scan" on 
grails-core.git/build/vulnerability-scan-plugin has succeeded.
Run started by GitHub user matrei (triggered by matrei).

Head commit for run:
38b83f6a135d8c0ae9625fad9f9c925df1689c75 / Mattias Reichel 
<[email protected]>
Exclude logback CVE-2026-104721 alongside CVE-2026-19880

CVE-2026-104721 is the follow-up to CVE-2026-19880: the 1.6.3 fix for
MDCBasedDiscriminator was insufficient and the new fix ships only in
logback 1.6.5. There is no 1.5.x release after 1.5.38, so it is excluded
for the same reason as CVE-2026-19880, which both exclusions now share,
and both are removed once a Spring Boot release manages logback 1.6.5.

Report URL: https://github.com/apache/grails-core/actions/runs/37486335333

With regards,
GitHub Actions via GitBox

Reply via email to