Repository navigation
14.1.5 Dependency & security updates
@
Highlights
This is a maintenance release focused on dependency and security updates. No API changes — it is a drop-in replacement for 14.1.0.
Security
Updated jackson-databind from 2.20.0 to 2.22.1, resolving 5 Dependabot advisories (2 high, 3 moderate):
- PolymorphicTypeValidator bypass via generic type parameters (high)
- PolymorphicTypeValidator array subtype allowlist bypass (high)
- InetSocketAddress deserialization SSRF via eager DNS resolution (moderate)
- Case-insensitive deserialization bypassing
@JsonIgnoreProperties(moderate) @JsonIgnoreon a Record bypassed with PropertyNamingStrategy (moderate)
Dependency updates
- commons-codec 1.19.0 → 1.22.0
- commons-io 2.20.0 → 2.22.0
- commons-lang3 3.19.0 → 3.20.0
- jaxb-runtime 4.0.6 → 4.0.9 (test jaxb-impl aligned to 4.0.9)
- central-publishing-maven-plugin 0.9.0 → 0.11.0
Documentation & tooling
- Fixed the Maven Central coordinates in the README usage example (
org.aarboard.nextcloud:nextcloud-api) - Removed the obsolete oss.sonatype.org snapshot badge
- Added Dependabot configuration for Maven and GitHub Actions
Requires Java 11+.
@