Skip to content

[RUN-4933] Bump rundeck-core to 6.2.0-20260908 (CVE-2026-19032) - #90

Merged
ronaveva merged 1 commit into
mainfrom
security/CVE-2026-19032-jackson
Sep 11, 2026
Merged

[RUN-4933] Bump rundeck-core to 6.2.0-20260908 (CVE-2026-19032)#90
ronaveva merged 1 commit into
mainfrom
security/CVE-2026-19032-jackson

Conversation

@fdevans

@fdevans fdevans commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

What

Bumps rundeck-core from 6.1.0-20260803 to 6.2.0-20260908.

Why

CVE-2026-19032: 6.1.0-20260803 pulls in a vulnerable transitive
Jackson version. 6.2.0-20260908 includes the fix.

Note

6.2.0-20260908 was published today. If the CI build here fails to
resolve it, that's expected propagation lag on the Sonatype snapshots
feed, not a real problem with this change - rerun the build once it's
synced.

rundeck-core 6.1.0-20260803 pulls in a vulnerable transitive Jackson
version (CVE-2026-19032). 6.2.0-20260908 includes the fix.
@fdevans
fdevans requested review from a team and a lite review from Copilot September 8, 2026 22:20

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The change is a core dependency bump to a very recent build with limited publicly available release detail, so a human should confirm dependency resolution and compatibility via CI and/or upstream release notes before merging.

Pull request overview

Updates this plugin’s build-time Rundeck API dependency to the newly published rundeck-core build that is intended to address CVE-2026-19032 (vulnerable transitive Jackson) referenced in the PR description.

Changes:

  • Bump org.rundeck:rundeck-core from 6.1.0-20260803 to 6.2.0-20260908 in the Gradle version catalog.
File summaries
File Description
gradle/libs.versions.toml Updates the rundeckCore version used by the Gradle dependency catalog.
Review details
  • Files reviewed: 1/1 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@fdevans fdevans changed the title Bump rundeck-core to 6.2.0-20260908 (CVE-2026-19032) [RUN-4933] Bump rundeck-core to 6.2.0-20260908 (CVE-2026-19032) Sep 8, 2026

@ronaveva ronaveva left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@ronaveva
ronaveva merged commit e2f6f05 into main Sep 11, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants