See <https://ci-builds.apache.org/job/Struts/job/Struts-master-dependency-check/265/display/redirect?page=changes>
Changes: [github] WW-5711 fix(conversion): bound fraction digits when formatting BigDecimal (#1887) [github] build(deps): bump mikepenz/action-junit-report from 6.4.2 to 6.5.0 (#1900) [github] build(deps): bump actions/setup-java from 5 to 6 (#1899) [github] build(deps): bump org.easymock:easymock from 5.6.0 to 5.7.0 (#1898) [github] build(deps): bump com.fasterxml.jackson:jackson-bom from 2.22.1 to 2.22.2 (#1897) [github] build(deps): bump ognl:ognl from 3.4.11 to 3.4.12 (#1895) [github] build(deps): bump github/codeql-action from 4.37.8 to 4.37.9 (#1894) [github] build(deps): bump org.apache.maven:apache-maven from 3.9.9 to 3.9.16 (#1892) [github] build(deps): bump org.freemarker:freemarker from 2.3.34 to 2.3.35 (#1891) [github] chore: gate reply drafting in triaging-security-reports skill (#1901) [github] WW-5712 Cover Jackson any-setters in REST parameter authorization (#1889) [Lukasz Lenart] WW-5717 build: bump Spring Framework to 7.0.9 in the jakartaee11 profile [github] build(deps): bump org.apache.felix:maven-bundle-plugin from 6.1.0 to 6.1.2 (#1910) [github] build(deps-dev): bump org.apache.maven.plugins:maven-failsafe-plugin from 3.5.6 to 3.6.0 (#1909) [github] build(deps): bump org.htmlunit:htmlunit from 5.4.0 to 5.5.0 (#1906) [github] build(deps-dev): bump byte-buddy.version from 1.18.12 to 1.18.13 (#1904) [github] WW-5716 fix(tiles): bound the per-locale definition caches (#1902) [github] docs: frame CVE-at-release-time as PMC practice, not a rule (#1917) [github] WW-3226 test: pin which value wins for each alias/params ordering (#1918) [github] WW-3245 feat(jasperreports): fill from report parameters when no dataSource or connection is set (#1919) [github] WW-5729 fix(jasperreports): override HashMap.get/containsKey in ValueStackShadowMap (#1920) [github] WW-5731 fix(jasperreports7): stop using the field delimiter as the CSV record delimiter (#1921) [github] WW-5732 fix(jasperreports7): match the report format case-insensitively (#1922) [github] WW-5733 fix(jasperreports7): stop closing the response stream before the report is written (#1923) [github] WW-5734 test(jasperreports7): run the plugin end-to-end on an embedded Tomcat (#1924) [github] WW-5735 build(jasperreports7): declare jasperreports as provided (#1926) [github] WW-5723 Bound the request body read in the REST plugin (#1912) [github] WW-5724 fix(core): hand out a clone of the cached MessageFormat (#1914) [github] build(deps-dev): bump org.apache.tomcat.embed:tomcat-embed-core (#1925) [github] WW-5725 Authorize the buffered creator path in AuthorizingSettableBeanProperty (#1916) [github] WW-5669 Honour struts.csp.nonceSource alongside struts.csp.nonce.source (#1927) [github] WW-5670 fix(core): parse struts.locale once and stop mislabelling the fallback locale (#1928) [github] WW-5686 test(core): stop DateTest.testJavaSqlDate racing the clock (#1929) [github] WW-5687 feat(core): clear the conversion and validator caches on Dispatcher.cleanup() (#1930) [github] WW-5709 fix(core): recognise fluent setters in @StrutsParameter enforcement (#1931) [github] WW-5710 fix(core): prime the OGNL allowlist against the action as well as the model (#1932) [github] WW-5663 fix(core): hand a WithLazyParams interceptor its own mapping's params (#1933) [github] WW-5702 fix(core): close the scope gaps in HTML5 constraint derivation (#1934) [github] WW-5702 fix(core): tighten the HTML5 constraint provider's attribute hygiene (#1935) [github] WW-5702 test(core): render pattern, required-on-radio and required-on-file end to end (#1936) [github] WW-5740 fix(core): resolve visitor-nested constraint messages like validation does (#1937) [github] WW-5703 fix(core): keep the HTML5 pattern from rejecting blank input the regex validator skips (#1938) [github] WW-5704 fix(core): emit required on radio/file only when the bound value would fail the validator (#1939) [github] WW-5715 fix(rest): authorize REST body properties by Java member name, not wire name (#1940) [github] WW-5726 fix(rest): decline the in-place merge of a polymorphic REST body property (#1941) [github] WW-5727 fix(rest): authorize the @JsonIdentityInfo id property (#1943) [github] WW-5745 fix(rest): keep the read-time verdict for a forward-referenced property (#1944) [github] WW-5746 fix(rest): authorize a bean-typed @JsonIdentityInfo id's members under the id path (#1945) [github] WW-5747 fix(rest): leave the parser at the end of an object the redaction wrapper drops (#1946) [github] WW-5748 fix(rest): let Jackson XML's deserializer modifier see the bean deserializer (#1947) [github] WW-5720 fix(rest): log any-setter dynamic-key rejections once per request (#1948) [github] WW-3353 fix(junit): make StrutsRestTestCase work against a REST/Convention app (#1956) [github] WW-5718 fix(rest,bean-validation): add the resource-isolation interceptors to the plugin default stacks (#1957) [github] WW-5749 fix(rest): write nothing from the XML handlers when there is no target (#1959) [github] WW-5713 fix(tiles): fail closed for legacy Tiles OGNL evaluation (#1890) [github] WW-5713 refactor(tiles): resolve the legacy OGNL flag from the container's own ServletContext (#1961) [github] WW-5719 Pin Maven distribution checksum (#1942) [github] WW-5743 fix(convention): rank path-spanning ** patterns after single-segment ones (#1962) [github] docs: state the control test that separates hardening from a vulnerability (#1964) [github] docs(skills): send the [TEST] mail from the @apache.org identity (#1963) [github] build(ci): decide "does this need a build" in one reusable workflow (#1965) [github] build(deps-dev): bump org.codehaus.mojo:versions-maven-plugin from 2.21.0 to 2.22.0 (#1950) [github] build(deps-dev): bump org.codehaus.mojo:exec-maven-plugin from 3.6.3 to 3.6.4 (#1954) [github] build(deps): bump github/codeql-action from 4.37.9 to 4.38.0 (#1952) [github] build(deps-dev): bump org.apache.tomcat.embed:tomcat-embed-core from 10.1.59 to 11.0.26 (#1949) [github] ci: pin Scorecards checkout action by commit (#1966) [github] build(ci): test once on JDK 17 in Jenkins, reserve Jetty ports for the showcase ITs (#1967) ------------------------------------------ Started by timer Running as SYSTEM [EnvInject] - Loading node environment variables. Building remotely on builds24 (ubuntu) in workspace <https://ci-builds.apache.org/job/Struts/job/Struts-master-dependency-check/ws/> The recommended git tool is: NONE No credentials specified > git rev-parse --resolve-git-dir > <https://ci-builds.apache.org/job/Struts/job/Struts-master-dependency-check/ws/.git> > # timeout=10 Fetching changes from the remote Git repository > git config remote.origin.url https://gitbox.apache.org/repos/asf/struts.git > # timeout=10 Fetching upstream changes from https://gitbox.apache.org/repos/asf/struts.git > git --version # timeout=10 > git --version # 'git version 2.34.1' > git fetch --tags --force --progress -- > https://gitbox.apache.org/repos/asf/struts.git > +refs/heads/*:refs/remotes/origin/* # timeout=10 > git rev-parse refs/remotes/origin/main^{commit} # timeout=10 Checking out Revision e5fb8e91d7673792d77b661075e95e704991ccc4 (refs/remotes/origin/main) > git config core.sparsecheckout # timeout=10 > git checkout -f e5fb8e91d7673792d77b661075e95e704991ccc4 # timeout=10 Commit message: "build(ci): test once on JDK 17 in Jenkins, reserve Jetty ports for the showcase ITs (#1967)" > git rev-list --no-walk 98fb891aac36b338d054425be129f3cd8ddd7fe9 # timeout=10 ERROR: No tool found matching MAVEN_3_LATEST__HOME Setting MAVEN_3_LATEST_HOME=/home/jenkins/tools/maven/latest3 [Struts-master-dependency-check] $ /bin/sh -xe /tmp/jenkins13961259370196077262.sh + export MAVEN_OPTS=-Xms2g -Xmx2g + /home/jenkins/tools/maven/latest3/bin/mvn verify -Pdependency-check [INFO] Scanning for projects... [INFO] ------------------------------------------------------------------------ [INFO] Reactor Build Order: [INFO] [INFO] Struts 2 [pom] [INFO] Struts BOM [pom] [INFO] Struts Parent POM [pom] [INFO] Struts 2 Jakarta EE Compatible modules [pom] [INFO] Struts 2 Jakarta EE Compatible Velocity Tools View [jar] [INFO] Struts 2 Jakarta EE Compatible Velocity Tools Jsp [jar] [INFO] Struts 2 Core [jar] [INFO] Struts 2 Plugins [pom] [INFO] Struts 2 Async Plugin [jar] [INFO] Struts 2 Bean Validation Plugin [jar] [INFO] Struts 2 CDI Plugin [jar] [INFO] Struts 2 Spring Plugin [jar] [INFO] Struts 2 JUnit Plugin [jar] [INFO] Struts 2 Velocity Plugin [jar] [INFO] Struts 2 Configuration Browser Plugin [jar] [INFO] Struts 2 Convention Plugin [jar] [INFO] Struts 2 Jasper Reports Plugin [jar] [INFO] Struts 2 Jasper Reports 7 Plugin [EXPERIMENTAL] [jar] [INFO] Struts 2 Java Templates Plugin [jar] [INFO] Struts 2 JFreeChart Plugin [jar] [INFO] Struts 2 JSON Plugin [jar] [INFO] Struts 2 REST Plugin [jar] [INFO] Struts 2 TestNG Plugin [jar] [INFO] Struts 2 Tiles Plugin [jar] [INFO] Struts 2 XSLT Plugin [jar] [INFO] Struts 2 Webapps [pom] [INFO] Struts 2 Showcase Webapp [war] [INFO] Struts 2 Rest Showcase Webapp [war] [INFO] Struts 2 Assembly [pom] [INFO] [INFO] -----------------< org.apache.struts:struts2-project >------------------ [INFO] Building Struts 2 7.4.0-SNAPSHOT [1/29] [INFO] from pom.xml [INFO] --------------------------------[ pom ]--------------------------------- [INFO] [INFO] --- enforcer:3.6.3:enforce (enforce) @ struts2-project --- [INFO] Rule 0: org.apache.maven.enforcer.rules.dependency.BannedDependencies passed [INFO] [INFO] --- enforcer:3.6.3:enforce (enforce-maven-version) @ struts2-project --- [INFO] Rule 0: org.apache.maven.enforcer.rules.version.RequireMavenVersion passed [INFO] [INFO] --- enforcer:3.6.3:enforce (enforce-java-version) @ struts2-project --- [INFO] Rule 0: org.apache.maven.enforcer.rules.version.RequireJavaVersion passed [INFO] [INFO] --- dependency-check:13.0.0:check (default) @ struts2-project --- [INFO] Checking for updates [ERROR] Error updating the NVD Data org.owasp.dependencycheck.data.update.exception.UpdateException: Error updating the NVD Data at org.owasp.dependencycheck.data.update.NvdApiDataSource.processApi (NvdApiDataSource.java:387) at org.owasp.dependencycheck.data.update.NvdApiDataSource.update (NvdApiDataSource.java:128) at org.owasp.dependencycheck.Engine.doUpdates (Engine.java:873) at org.owasp.dependencycheck.Engine.initializeAndUpdateDatabase (Engine.java:678) at org.owasp.dependencycheck.Engine.analyzeDependencies (Engine.java:605) at org.owasp.dependencycheck.maven.BaseDependencyCheckMojo.runCheck (BaseDependencyCheckMojo.java:2072) at org.owasp.dependencycheck.maven.BaseDependencyCheckMojo.execute (BaseDependencyCheckMojo.java:1272) at org.apache.maven.plugin.DefaultBuildPluginManager.executeMojo (DefaultBuildPluginManager.java:126) at org.apache.maven.lifecycle.internal.MojoExecutor.doExecute2 (MojoExecutor.java:328) at org.apache.maven.lifecycle.internal.MojoExecutor.doExecute (MojoExecutor.java:316) at org.apache.maven.lifecycle.internal.MojoExecutor.execute (MojoExecutor.java:212) at org.apache.maven.lifecycle.internal.MojoExecutor.execute (MojoExecutor.java:174) at org.apache.maven.lifecycle.internal.MojoExecutor.access$000 (MojoExecutor.java:75) at org.apache.maven.lifecycle.internal.MojoExecutor$1.run (MojoExecutor.java:162) at org.apache.maven.plugin.DefaultMojosExecutionStrategy.execute (DefaultMojosExecutionStrategy.java:39) at org.apache.maven.lifecycle.internal.MojoExecutor.execute (MojoExecutor.java:159) at org.apache.maven.lifecycle.internal.LifecycleModuleBuilder.buildProject (LifecycleModuleBuilder.java:105) at org.apache.maven.lifecycle.internal.LifecycleModuleBuilder.buildProject (LifecycleModuleBuilder.java:73) at org.apache.maven.lifecycle.internal.builder.singlethreaded.SingleThreadedBuilder.build (SingleThreadedBuilder.java:53) at org.apache.maven.lifecycle.internal.LifecycleStarter.execute (LifecycleStarter.java:118) at org.apache.maven.DefaultMaven.doExecute (DefaultMaven.java:261) at org.apache.maven.DefaultMaven.doExecute (DefaultMaven.java:173) at org.apache.maven.DefaultMaven.execute (DefaultMaven.java:101) at org.apache.maven.cli.MavenCli.execute (MavenCli.java:919) at org.apache.maven.cli.MavenCli.doMain (MavenCli.java:285) at org.apache.maven.cli.MavenCli.main (MavenCli.java:207) at jdk.internal.reflect.NativeMethodAccessorImpl.invoke0 (Native Method) at jdk.internal.reflect.NativeMethodAccessorImpl.invoke (NativeMethodAccessorImpl.java:77) at jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke (DelegatingMethodAccessorImpl.java:43) at java.lang.reflect.Method.invoke (Method.java:569) at org.codehaus.plexus.classworlds.launcher.Launcher.launchEnhanced (Launcher.java:255) at org.codehaus.plexus.classworlds.launcher.Launcher.launch (Launcher.java:201) at org.codehaus.plexus.classworlds.launcher.Launcher.mainWithExitCode (Launcher.java:362) at org.codehaus.plexus.classworlds.launcher.Launcher.main (Launcher.java:314) Caused by: io.github.jeremylong.openvulnerability.client.nvd.NvdApiException: Invalid API Key, length of 0 too short to provided a masked partial key at io.github.jeremylong.openvulnerability.client.nvd.NvdCveClient._next (NvdCveClient.java:436) at io.github.jeremylong.openvulnerability.client.nvd.NvdCveClient.next (NvdCveClient.java:356) at org.owasp.dependencycheck.data.update.NvdApiDataSource.processApi (NvdApiDataSource.java:343) at org.owasp.dependencycheck.data.update.NvdApiDataSource.update (NvdApiDataSource.java:128) at org.owasp.dependencycheck.Engine.doUpdates (Engine.java:873) at org.owasp.dependencycheck.Engine.initializeAndUpdateDatabase (Engine.java:678) at org.owasp.dependencycheck.Engine.analyzeDependencies (Engine.java:605) at org.owasp.dependencycheck.maven.BaseDependencyCheckMojo.runCheck (BaseDependencyCheckMojo.java:2072) at org.owasp.dependencycheck.maven.BaseDependencyCheckMojo.execute (BaseDependencyCheckMojo.java:1272) at org.apache.maven.plugin.DefaultBuildPluginManager.executeMojo (DefaultBuildPluginManager.java:126) at org.apache.maven.lifecycle.internal.MojoExecutor.doExecute2 (MojoExecutor.java:328) at org.apache.maven.lifecycle.internal.MojoExecutor.doExecute (MojoExecutor.java:316) at org.apache.maven.lifecycle.internal.MojoExecutor.execute (MojoExecutor.java:212) at org.apache.maven.lifecycle.internal.MojoExecutor.execute (MojoExecutor.java:174) at org.apache.maven.lifecycle.internal.MojoExecutor.access$000 (MojoExecutor.java:75) at org.apache.maven.lifecycle.internal.MojoExecutor$1.run (MojoExecutor.java:162) at org.apache.maven.plugin.DefaultMojosExecutionStrategy.execute (DefaultMojosExecutionStrategy.java:39) at org.apache.maven.lifecycle.internal.MojoExecutor.execute (MojoExecutor.java:159) at org.apache.maven.lifecycle.internal.LifecycleModuleBuilder.buildProject (LifecycleModuleBuilder.java:105) at org.apache.maven.lifecycle.internal.LifecycleModuleBuilder.buildProject (LifecycleModuleBuilder.java:73) at org.apache.maven.lifecycle.internal.builder.singlethreaded.SingleThreadedBuilder.build (SingleThreadedBuilder.java:53) at org.apache.maven.lifecycle.internal.LifecycleStarter.execute (LifecycleStarter.java:118) at org.apache.maven.DefaultMaven.doExecute (DefaultMaven.java:261) at org.apache.maven.DefaultMaven.doExecute (DefaultMaven.java:173) at org.apache.maven.DefaultMaven.execute (DefaultMaven.java:101) at org.apache.maven.cli.MavenCli.execute (MavenCli.java:919) at org.apache.maven.cli.MavenCli.doMain (MavenCli.java:285) at org.apache.maven.cli.MavenCli.main (MavenCli.java:207) at jdk.internal.reflect.NativeMethodAccessorImpl.invoke0 (Native Method) at jdk.internal.reflect.NativeMethodAccessorImpl.invoke (NativeMethodAccessorImpl.java:77) at jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke (DelegatingMethodAccessorImpl.java:43) at java.lang.reflect.Method.invoke (Method.java:569) at org.codehaus.plexus.classworlds.launcher.Launcher.launchEnhanced (Launcher.java:255) at org.codehaus.plexus.classworlds.launcher.Launcher.launch (Launcher.java:201) at org.codehaus.plexus.classworlds.launcher.Launcher.mainWithExitCode (Launcher.java:362) at org.codehaus.plexus.classworlds.launcher.Launcher.main (Launcher.java:314) [INFO] Updating CISA Known Exploited Vulnerability list: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json [INFO] Begin database defrag [INFO] End database defrag (12847 ms) [INFO] Check for updates complete (15440 ms) [WARNING] Unable to update 1 or more Cached Web DataSource, using local data instead. Results may not include recent vulnerabilities. [INFO] Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user's risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report. About ODC: https://dependency-check.github.io/DependencyCheck/general/internals.html False Positives: https://dependency-check.github.io/DependencyCheck/general/suppression.html [INFO] Analysis Started [INFO] Finished File Name Analyzer (0 seconds) [INFO] Finished Dependency Merging Analyzer (0 seconds) [INFO] Finished Hint Analyzer (0 seconds) [INFO] Created CPE Index (4 seconds) [INFO] Finished CPE Analyzer (5 seconds) [INFO] Finished False Positive Analyzer (0 seconds) [INFO] Finished NVD CVE Analyzer (0 seconds) [WARNING] Sonatype OSS Index Analyzer disabled due to missing credentials. Authentication with token is now required, and OSS Index is migrating to Sonatype Guide. See https://dependency-check.github.io/DependencyCheck/analyzers/oss-index-analyzer.html for more information on authentication with Sonatype Guide OSS Index. [INFO] Finished Vulnerability Suppression Analyzer (0 seconds) [INFO] Finished Known Exploited Vulnerability Analyzer (0 seconds) [INFO] Finished Dependency Bundling Analyzer (0 seconds) [INFO] Finished Unused Suppression Rule Analyzer (0 seconds) [INFO] Analysis Complete (5 seconds) [INFO] Writing HTML report to: <https://ci-builds.apache.org/job/Struts/job/Struts-master-dependency-check/ws/target/dependency-check-report.html> [INFO] ------------------------------------------------------------------------ [INFO] Reactor Summary for Struts 2 7.4.0-SNAPSHOT: [INFO] [INFO] Struts 2 ........................................... FAILURE [ 27.177 s] [INFO] Struts BOM ......................................... SKIPPED [INFO] Struts Parent POM .................................. SKIPPED [INFO] Struts 2 Jakarta EE Compatible modules ............. SKIPPED [INFO] Struts 2 Jakarta EE Compatible Velocity Tools View . SKIPPED [INFO] Struts 2 Jakarta EE Compatible Velocity Tools Jsp .. SKIPPED [INFO] Struts 2 Core ...................................... SKIPPED [INFO] Struts 2 Plugins ................................... SKIPPED [INFO] Struts 2 Async Plugin .............................. SKIPPED [INFO] Struts 2 Bean Validation Plugin .................... SKIPPED [INFO] Struts 2 CDI Plugin ................................ SKIPPED [INFO] Struts 2 Spring Plugin ............................. SKIPPED [INFO] Struts 2 JUnit Plugin .............................. SKIPPED [INFO] Struts 2 Velocity Plugin ........................... SKIPPED [INFO] Struts 2 Configuration Browser Plugin .............. SKIPPED [INFO] Struts 2 Convention Plugin ......................... SKIPPED [INFO] Struts 2 Jasper Reports Plugin ..................... SKIPPED [INFO] Struts 2 Jasper Reports 7 Plugin [EXPERIMENTAL] .... SKIPPED [INFO] Struts 2 Java Templates Plugin ..................... SKIPPED [INFO] Struts 2 JFreeChart Plugin ......................... SKIPPED [INFO] Struts 2 JSON Plugin ............................... SKIPPED [INFO] Struts 2 REST Plugin ............................... SKIPPED [INFO] Struts 2 TestNG Plugin ............................. SKIPPED [INFO] Struts 2 Tiles Plugin .............................. SKIPPED [INFO] Struts 2 XSLT Plugin ............................... SKIPPED [INFO] Struts 2 Webapps ................................... SKIPPED [INFO] Struts 2 Showcase Webapp ........................... SKIPPED [INFO] Struts 2 Rest Showcase Webapp ...................... SKIPPED [INFO] Struts 2 Assembly .................................. SKIPPED [INFO] ------------------------------------------------------------------------ [INFO] BUILD FAILURE [INFO] ------------------------------------------------------------------------ [INFO] Total time: 29.800 s [INFO] Finished at: 2026-09-22T06:39:45Z [INFO] ------------------------------------------------------------------------ [ERROR] Failed to execute goal org.owasp:dependency-check-maven:13.0.0:check (default) on project struts2-project: One or more exceptions occurred during dependency-check analysis: One or more exceptions occurred during analysis: [ERROR] UpdateException: Error updating the NVD Data [ERROR] caused by NvdApiException: Invalid API Key, length of 0 too short to provided a masked partial key [ERROR] -> [Help 1] [ERROR] [ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch. [ERROR] Re-run Maven using the -X switch to enable full debug logging. [ERROR] [ERROR] For more information about the errors and possible solutions, please read the following articles: [ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/MojoExecutionException Build step 'Execute shell' marked build as failure ERROR: No tool found matching MAVEN_3_LATEST__HOME Setting MAVEN_3_LATEST_HOME=/home/jenkins/tools/maven/latest3
