Skip to content

Update ASzc/change-string-case-action action to v8 - #43

Open
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/aszc-change-string-case-action-8.x
Open

Update ASzc/change-string-case-action action to v8#43
mend-for-github-com[bot] wants to merge 1 commit into
mainfrom
whitesource-remediate/aszc-change-string-case-action-8.x

Update ASzc/change-string-case-action action to v8

44fdadd
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Security Check failed May 4, 2026 in 2m 56s

Security Report

❗️Scan Warnings: The scan completed with warnings. The integration encountered issues with one or more projects in this repository. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.

Scan Details Report

maven

/tmp/ws-scm/WebGoat/pom.xml

Step Level Description Details
Preparing the project for scan ⚠Warn One or more of the installations failed [ERROR] [ERROR] Some problems were encountered while processing the POMs:
[FATAL] Non-resolvable parent POM for org.owasp.webgoat:webgoat:2023.4: The following artifacts could not be resolved: org.springframework.boot:spring-boot-starter-parent:pom:2.7.1 (absent): Could not transfer artifact org.springframework.boot:spring-boot-starter-parent:pom:2.7.1 from/to central (https://repo.maven.apache...
Resolving the project ⚠Warn Some problems occurred while performing the resolution operation
  • Failed to execute command: mvn org.apache.maven.plugins:maven-dependency-plugin:3.6.0:tree -DoutputFile=whitesource_mvn_dependency_tree.txt -Dverbose -DoutputType=text -T1 -B
    Error lines:
    [NOTE: Picked up JDK_JAVA_OPTIONS: --add-opens java.base/java.util=ALL-UNNAMED --add-opens java.base/sun.reflect.generics.reflectiveObjects=ALL-UNNAMED]
    Output lines:
    [[INFO] Scanning for project...
  • Fallback is used, returns direct dependencies only

You have successfully remediated 124 vulnerabilities, but introduced 3 new vulnerabilities in this branch.

❌ New vulnerabilities:
Vulnerability Severity CVSS Score Exploit Maturity EPSS Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2025-4641

Path to dependency file: /pom.xml

Path to vulnerable library: /pom.xml

Dependency Hierarchy:

-> ❌ webdrivermanager-4.3.1.jar (Vulnerable Library)

Critical 9.4 Not Defined 0.508% Direct webdrivermanager-4.3.1.jar webdrivermanager-4.3.1.jar https://github.com/bonigarcia/webdrivermanager.git - webdrivermanager-6.1.0,io.github.bonigarcia:webdrivermanager:6.1.0 None
CVE-2024-25710

Path to dependency file: /pom.xml

Path to vulnerable library: /pom.xml

Dependency Hierarchy:

-> ❌ commons-compress-1.21.jar (Vulnerable Library)

High 8.1 Not Defined 0.018% Direct commons-compress-1.21.jar commons-compress-1.21.jar 1.26.0 None
CVE-2024-26308

Path to dependency file: /pom.xml

Path to vulnerable library: /pom.xml

Dependency Hierarchy:

-> ❌ commons-compress-1.21.jar (Vulnerable Library)

Medium 5.5 Not Defined 0.392% Direct commons-compress-1.21.jar commons-compress-1.21.jar 1.26.0 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2022-31692 spring-security-core-5.7.2.jar
CVE-2026-40477 thymeleaf-spring5-3.0.15.RELEASE.jar
CVE-2026-40973 spring-boot-2.7.1.jar
CVE-2024-38809 spring-web-5.3.21.jar
CVE-2022-25857 snakeyaml-1.30.jar
CVE-2026-40974 spring-boot-autoconfigure-2.7.1.jar
CVE-2024-9823 jetty-servlets-9.4.48.v20220622.jar
CVE-2026-1225 logback-core-1.2.11.jar
CVE-2023-26049 jetty-server-9.4.48.v20220622.jar
CVE-2026-2332 jetty-http-9.4.48.v20220622.jar
CVE-2025-22228 spring-security-crypto-5.7.2.jar
CVE-2023-3223 undertow-servlet-2.2.18.Final.jar
CVE-2026-22746 spring-security-core-5.7.2.jar
CVE-2016-1000027 spring-web-5.3.21.jar
CVE-2026-40975 spring-boot-2.7.1.jar
WS-2026-0003 jackson-core-2.13.3.jar
CVE-2023-36478 jetty-http-9.4.48.v20220622.jar
CVE-2026-22735 spring-web-5.3.21.jar
CVE-2023-24998 commons-fileupload-1.4.jar
CVE-2021-23369 handlebars-4.0.7.jar
CVE-2024-7885 undertow-core-2.2.18.Final.jar
CVE-2024-38820 spring-context-5.3.21.jar
CVE-2026-22732 spring-security-web-5.7.2.jar
CVE-2024-5971 undertow-core-2.2.18.Final.jar
CVE-2025-41242 spring-beans-5.3.21.jar
CVE-2025-9784 undertow-core-2.2.18.Final.jar
CVE-2025-12543 undertow-core-2.2.18.Final.jar
CVE-2025-41249 spring-core-5.3.21.jar
CVE-2023-4639 undertow-core-2.2.18.Final.jar
CVE-2022-2053 undertow-core-2.2.18.Final.jar
CVE-2023-40167 jetty-http-9.4.48.v20220622.jar
CVE-2025-22233 spring-context-5.3.21.jar
CVE-2023-1973 undertow-core-2.2.18.Final.jar
CVE-2024-38828 spring-webmvc-5.3.21.jar
CVE-2026-22733 spring-boot-actuator-autoconfigure-2.7.1.jar
CVE-2024-38816 spring-webmvc-5.3.21.jar
CVE-2024-6763 jetty-http-9.4.48.v20220622.jar
CVE-2022-41854 snakeyaml-1.30.jar
CVE-2022-38750 snakeyaml-1.30.jar
CVE-2026-22745 spring-webmvc-5.3.21.jar
CVE-2024-12798 logback-core-1.2.11.jar
CVE-2023-34055 spring-boot-actuator-2.7.1.jar
CVE-2022-38752 snakeyaml-1.30.jar
CVE-2023-20862 spring-security-core-5.7.2.jar
CVE-2024-38827 spring-security-core-5.7.2.jar
CVE-2026-24400 assertj-core-3.22.0.jar
CVE-2023-20863 spring-expression-5.3.21.jar
CVE-2025-41242 spring-webmvc-5.3.21.jar
CVE-2024-38828 spring-web-5.3.21.jar
CVE-2026-3260 undertow-core-2.2.18.Final.jar
CVE-2024-22262 spring-web-5.3.21.jar
CVE-2023-38286 thymeleaf-3.0.15.RELEASE.jar
CVE-2026-22735 spring-webmvc-5.3.21.jar
CVE-2024-38819 spring-webmvc-5.3.21.jar
CVE-2024-13009 jetty-server-9.4.48.v20220622.jar
CVE-2023-6378 logback-core-1.2.11.jar
CVE-2025-48976 commons-fileupload-1.4.jar
CVE-2024-22259 spring-web-5.3.21.jar
WS-2023-0236 jetty-xml-9.4.48.v20220622.jar
CVE-2023-20860 spring-webmvc-5.3.21.jar
CVE-2026-22737 spring-webmvc-5.3.21.jar
CVE-2026-22733 spring-boot-starter-actuator-2.7.1.jar
CVE-2024-22257 spring-security-core-5.7.2.jar
CVE-2025-52999 jackson-core-2.13.3.jar
CVE-2024-12798 logback-classic-1.2.11.jar
CVE-2026-40478 thymeleaf-3.0.15.RELEASE.jar
WS-2022-0468 jackson-core-2.13.3.jar
CVE-2026-22754 spring-security-config-5.7.2.jar
CVE-2023-5685 xnio-api-3.8.7.Final.jar
CVE-2022-1259 undertow-core-2.2.18.Final.jar
CVE-2026-40977 spring-boot-2.7.1.jar
CVE-2024-4027 undertow-core-2.2.18.Final.jar
CVE-2025-11143 jetty-http-9.4.48.v20220622.jar
CVE-2024-31573 xmlunit-core-2.9.0.jar
CVE-2022-38749 snakeyaml-1.30.jar
CVE-2022-38751 snakeyaml-1.30.jar
CVE-2022-31692 spring-security-web-5.7.2.jar
CVE-2024-38828 spring-core-5.3.21.jar
CVE-2024-38827 spring-security-web-5.7.2.jar
CVE-2022-42004 jackson-databind-2.13.3.jar
CVE-2023-36479 jetty-servlets-9.4.48.v20220622.jar
CVE-2024-12801 logback-core-1.2.11.jar
CVE-2022-1471 snakeyaml-1.30.jar
CVE-2023-20873 spring-boot-actuator-autoconfigure-2.7.1.jar
CVE-2024-1635 undertow-core-2.2.18.Final.jar
CVE-2024-3653 undertow-servlet-2.2.18.Final.jar
CVE-2024-3653 undertow-core-2.2.18.Final.jar
CVE-2022-0084 xnio-api-3.8.7.Final.jar
CVE-2026-40477 thymeleaf-3.0.15.RELEASE.jar
CVE-2024-38808 spring-expression-5.3.21.jar
CVE-2023-34034 spring-security-config-5.7.2.jar
CVE-2024-38821 spring-security-web-5.7.2.jar
CVE-2024-1459 undertow-core-2.2.18.Final.jar
CVE-2026-22740 spring-web-5.3.21.jar
CVE-2024-38827 spring-security-crypto-5.7.2.jar
CVE-2026-0603 hibernate-core-5.6.9.Final.jar
CVE-2023-26049 jetty-http-9.4.48.v20220622.jar
CVE-2026-22753 spring-security-config-5.7.2.jar
CVE-2022-4492 undertow-core-2.2.18.Final.jar
CVE-2024-3884 undertow-core-2.2.18.Final.jar
CVE-2024-38820 spring-core-5.3.21.jar
CVE-2025-22235 spring-boot-2.7.1.jar
CVE-2023-20862 spring-security-web-5.7.2.jar
CVE-2024-6763 jetty-server-9.4.48.v20220622.jar
CVE-2023-5379 undertow-core-2.2.18.Final.jar
CVE-2025-48924 commons-lang3-3.12.0.jar
CVE-2025-22235 spring-boot-actuator-autoconfigure-2.7.1.jar
CVE-2026-22741 spring-webmvc-5.3.21.jar
CVE-2026-40478 thymeleaf-spring5-3.0.15.RELEASE.jar
CVE-2023-1108 undertow-core-2.2.18.Final.jar
CVE-2025-11226 logback-core-1.2.11.jar
CVE-2022-42003 jackson-databind-2.13.3.jar
CVE-2024-8184 jetty-server-9.4.48.v20220622.jar
CVE-2023-1370 json-smart-2.4.8.jar
CVE-2023-20883 spring-boot-autoconfigure-2.7.1.jar
CVE-2024-22243 spring-web-5.3.21.jar
CVE-2023-6378 logback-classic-1.2.11.jar
CVE-2023-51074 json-path-2.7.0.jar
CVE-2024-38827 spring-security-config-5.7.2.jar
CVE-2023-20861 spring-expression-5.3.21.jar
CVE-2023-26048 jetty-server-9.4.48.v20220622.jar
CVE-2024-6162 undertow-core-2.2.18.Final.jar
CVE-2024-38820 spring-web-5.3.21.jar
CVE-2024-38820 spring-webmvc-5.3.21.jar

Base branch total remaining vulnerabilities: 189
Base branch commit: c84be84af55fb04e04baf4725d37d15807a4e6da


Total libraries scanned: 27

Scan token: d69107a2497d4a068460367967bdf337