The GitHub Actions job "Vulnerability Scan" on grails-core.git/build/vulnerability-scan-plugin has succeeded. Run started by GitHub user matrei (triggered by matrei).
Head commit for run: 38b83f6a135d8c0ae9625fad9f9c925df1689c75 / Mattias Reichel <[email protected]> Exclude logback CVE-2026-104721 alongside CVE-2026-19880 CVE-2026-104721 is the follow-up to CVE-2026-19880: the 1.6.3 fix for MDCBasedDiscriminator was insufficient and the new fix ships only in logback 1.6.5. There is no 1.5.x release after 1.5.38, so it is excluded for the same reason as CVE-2026-19880, which both exclusions now share, and both are removed once a Spring Boot release manages logback 1.6.5. Report URL: https://github.com/apache/grails-core/actions/runs/37486335333 With regards, GitHub Actions via GitBox
