Conversation
jsoup 1.23.1 is flagged by Snyk (CVE-2026-75140) for unbounded memory growth in XmlTreeBuilder's namespace scope tracking. Fixed upstream in 1.23.2 via a rewritten NamespaceBindings scope tracker that replaces the per-element namespace-map copy. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
fix: upgrade jsoup dependency to version 1.23.2
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
🔒 Security Scan Results
⏱️ SLA Breach Summary
✅ BUILD PASSED - All security checks passed |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
No unresolved blocking issues were identified in the reviewed changes.
Review effort: Lite
Findings: None
What changed in this PR
Back-merges the August release changes from master into development, including SDK metadata, a jsoup security update, and CODEOWNERS revisions.
Changes:
- Bumps the SDK version to 1.14.1.
- Upgrades jsoup to 1.23.2 and documents the security fix.
- Updates repository ownership rules.
| File | Description |
|---|---|
pom.xml |
Updates project and jsoup versions. |
changelog.md |
Documents the 1.14.1 release and security fix. |
.github/CODEOWNERS |
Revises repository ownership assignments. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Superseded by #271. That PR comes from a back-merge branch that is up to date with development; this one was out of date because it came straight from master. |
Back-merge of
masterintodevelopmentfollowing DX | 31-08-2026 | Release.