Skip to content

Update Mend: high confidence minor and patch dependency updates

7b39513
Select commit
Loading
Failed to load commit list.
Open

Update Mend: high confidence minor and patch dependency updates #3

Update Mend: high confidence minor and patch dependency updates
7b39513
Select commit
Loading
Failed to load commit list.
Mend for GitHub.com / Mend Security Check failed Apr 18, 2026 in 8m 39s

Security Report

❗️Scan Incomplete: The scan completed with partial failure. The integration encountered issues with one or more projects in this repository, preventing their scan. The errors occurred in the following package managers: gradle. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.

Scan Details Report

gradle

/tmp/ws-scm/elasticsearch/build.gradle

Step Level Description Details
Preparing the project for scan ⚠Warn One or more of the installations failed failed running mend init script (mendDeps):
NOTE: Picked up JDK_JAVA_OPTIONS: --add-opens java.base/java.util=ALL-UNNAMED --add-opens java.base/sun.reflect.generics.reflectiveObjects=ALL-UNNAMED

FAILURE: Build failed with an exception.

* Where:
Settings file '/tmp/ws-scm/elasticsearch/settings.gradle' line: 20

* What went wrong:
Error resolving plugin [id: 'com.gradle.develocity', version: '...

You have successfully remediated 2 vulnerabilities, but introduced 2 new vulnerabilities in this branch.

❌ New vulnerabilities:
Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue Reachability
CVE-2025-37731

Vulnerable Source Files:

❌ /xpack/core/security/authc/pki/PkiRealmSettings.java

Medium 6.8 elasticsearchcbde7f456d7ccd98556302fccf3238bb4557fc91 None
CVE-2025-37731

Vulnerable Source Files:

❌ /common/ssl/DerParser.java

❌ /xpack/security/authc/pki/PkiRealm.java

Medium 6.8 elasticsearch097fc0654f9305e01402a06c82926bb04ebe5495 None

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2025-37731 elasticsearch-v8.15.0
CVE-2025-37731 elasticsearch-v8.14.1

Base branch total remaining vulnerabilities: 3
Base branch commit: null


Total libraries scanned: 31

Scan token: eb5e621846d94c51a68a1a03e3a657c3