Update Mend: high confidence minor and patch dependency updates #3
Mend for GitHub.com / Mend Security Check
failed
Apr 18, 2026 in 8m 39s
Security Report
❗️Scan Incomplete: The scan completed with partial failure. The integration encountered issues with one or more projects in this repository, preventing their scan. The errors occurred in the following package managers: gradle. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.
Scan Details Report
gradle
/tmp/ws-scm/elasticsearch/build.gradle
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | failed running mend init script (mendDeps): NOTE: Picked up JDK_JAVA_OPTIONS: --add-opens java.base/java.util=ALL-UNNAMED --add-opens java.base/sun.reflect.generics.reflectiveObjects=ALL-UNNAMED FAILURE: Build failed with an exception. * Where: Settings file '/tmp/ws-scm/elasticsearch/settings.gradle' line: 20 * What went wrong: Error resolving plugin [id: 'com.gradle.develocity', version: '... |
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
| 6.8 | elasticsearchcbde7f456d7ccd98556302fccf3238bb4557fc91 | None | |||||
CVE-2025-37731Vulnerable Source Files: ❌ /common/ssl/DerParser.java ❌ /xpack/security/authc/pki/PkiRealm.java |
6.8 | elasticsearch097fc0654f9305e01402a06c82926bb04ebe5495 | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2025-37731 | elasticsearch-v8.15.0 |
| CVE-2025-37731 | elasticsearch-v8.14.1 |
Base branch total remaining vulnerabilities: 3
Base branch commit: null
Total libraries scanned: 31
Scan token: eb5e621846d94c51a68a1a03e3a657c3
Loading