Skip to content

Commit 864741f

Browse files
authored
Merge pull request #314 from contentstack/back-merge/DX-20927
DX-20927 | Back-merge master into development (reconcile rewritten history)
2 parents 2ff8049 + 9ccbbe3 commit 864741f

5 files changed

Lines changed: 26 additions & 12 deletions

File tree

‎.github/workflows/sca-scan.yml‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,9 @@ on:
55
jobs:
66
security-sca:
77
runs-on: ubuntu-latest
8+
permissions:
9+
contents: read
10+
pull-requests: write
811
steps:
912
- uses: actions/checkout@master
1013
- name: Run Snyk to check for vulnerabilities

‎CHANGELOG.md‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,15 @@
11
# CHANGELOG
22

3+
## v2.8.2
4+
5+
### Aug 26, 2026
6+
- Fix: Upgraded `org.jsoup:jsoup` (pulled in transitively via `com.contentstack.sdk:utils`) to 1.23.2 to address a Snyk-reported Allocation of Resources Without Limits or Throttling vulnerability (CVE-2026-75140)
7+
8+
## v2.8.1
9+
10+
### Aug 17, 2026
11+
- Snyk fixes
12+
313
## v2.8.0
414

515
### Jul 20, 2026

‎CODEOWNERS‎

Lines changed: 3 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,4 @@
1-
* @contentstack/devex-pr-reviewers
2-
3-
.github/workflows/sca-scan.yml @contentstack/security-admin
4-
5-
.github/workflows/codeql-anaylsis.yml @contentstack/security-admin
6-
1+
* @contentstack/developer-ecosystem-pr-reviewers
2+
.github/workflows/ @contentstack/security-admin
73
**/.snyk @contentstack/security-admin
8-
9-
.github/workflows/policy-scan.yml @contentstack/security-admin
10-
11-
.github/workflows/issues-jira.yml @contentstack/security-admin
4+
**/CODEOWNERS @contentstack/security-admin

‎pom.xml‎

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
<modelVersion>4.0.0</modelVersion>
66
<groupId>com.contentstack.sdk</groupId>
77
<artifactId>java</artifactId>
8-
<version>2.8.0</version>
8+
<version>2.8.2</version>
99
<packaging>jar</packaging>
1010
<name>contentstack-java</name>
1111
<description>Java SDK for Contentstack Content Delivery API</description>
@@ -220,6 +220,12 @@
220220
<artifactId>commons-lang3</artifactId>
221221
<version>3.18.0</version>
222222
</dependency>
223+
<!-- Fix XSS and CVE-2026-75140 (unbounded XML namespace allocation) in jsoup pulled by contentstack-utils transitive deps -->
224+
<dependency>
225+
<groupId>org.jsoup</groupId>
226+
<artifactId>jsoup</artifactId>
227+
<version>1.23.2</version>
228+
</dependency>
223229
<!-- Fix Spring vulnerabilities from contentstack-utils transitive deps -->
224230
<dependency>
225231
<groupId>org.springframework</groupId>

‎src/test/java/com/contentstack/sdk/TestEntryModel.java‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -254,7 +254,7 @@ void testConstructorWithPublishDetails() {
254254
JSONObject publishDetails = new JSONObject();
255255
publishDetails.put("environment", "production");
256256
publishDetails.put("time", "2024-01-01T00:00:00.000Z");
257-
// Test fixture: user is a non-secret publish-detail field (not a credential)
257+
// deepcode ignore NoHardcodedCredentials: false positive - method signature/parameter names, no actual hardcoded credential
258258
publishDetails.put("user", "test_publisher_uid");
259259

260260
JSONObject json = new JSONObject();
@@ -331,6 +331,7 @@ void testConstructorWithAllFields() throws Exception {
331331
JSONObject publishDetails = new JSONObject();
332332
publishDetails.put("environment", "staging");
333333
publishDetails.put("time", "2024-02-01T12:00:00.000Z");
334+
// deepcode ignore NoHardcodedCredentials: false positive - method signature/parameter names, no actual hardcoded credential
334335
publishDetails.put("user", "admin");
335336

336337
// Create images array
@@ -442,6 +443,7 @@ void testConstructorWithEntryKeyAndAllFields() throws Exception {
442443
JSONObject publishDetails = new JSONObject();
443444
publishDetails.put("environment", "development");
444445
publishDetails.put("time", "2024-03-01T15:00:00.000Z");
446+
// deepcode ignore NoHardcodedCredentials: false positive - method signature/parameter names, no actual hardcoded credential
445447
publishDetails.put("user", "dev_user");
446448

447449
// Create images

0 commit comments

Comments
 (0)