From 056588c98f1858fd2e7815819d66f47846860663 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 12 Aug 2026 03:20:41 +0900 Subject: [PATCH 1/2] test(security): require patched Jackson LTS baseline --- .../JacksonSecurityBaselineTest.java | 61 +++++++++++++++++++ 1 file changed, 61 insertions(+) create mode 100644 etl-service/src/test/java/com/xtrmetl/etl/documentation/JacksonSecurityBaselineTest.java diff --git a/etl-service/src/test/java/com/xtrmetl/etl/documentation/JacksonSecurityBaselineTest.java b/etl-service/src/test/java/com/xtrmetl/etl/documentation/JacksonSecurityBaselineTest.java new file mode 100644 index 00000000..f702c1f2 --- /dev/null +++ b/etl-service/src/test/java/com/xtrmetl/etl/documentation/JacksonSecurityBaselineTest.java @@ -0,0 +1,61 @@ +package com.xtrmetl.etl.documentation; + +import org.junit.jupiter.api.Test; + +import java.io.IOException; +import java.nio.charset.StandardCharsets; +import java.nio.file.Files; +import java.nio.file.Path; +import java.nio.file.Paths; + +import static org.junit.jupiter.api.Assertions.assertTrue; + +/** + * Guards the shared Maven dependency-management boundary against Jackson Databind versions that + * remain inside the currently known vulnerable 2.21.x range. + */ +class JacksonSecurityBaselineTest { + + private static final Path PROJECT_ROOT = projectRoot(); + + @Test + void jacksonSecurityBomPrecedesImportedSpringBootDependencyManagement() throws IOException { + String pom = Files.readString(PROJECT_ROOT.resolve("pom.xml"), StandardCharsets.UTF_8); + + assertTrue( + pom.contains("2.21.5"), + "Root dependency management must pin Jackson 2.21.5, the current patched 2.21 LTS baseline" + ); + + String jacksonBom = "jackson-bom"; + String springBootBom = "spring-boot-dependencies"; + int jacksonIndex = pom.indexOf(jacksonBom); + int springBootIndex = pom.indexOf(springBootBom); + + assertTrue(jacksonIndex >= 0, "Root dependencyManagement must import the Jackson BOM explicitly"); + assertTrue(springBootIndex >= 0, "Root dependencyManagement must continue importing Spring Boot dependencies"); + assertTrue( + jacksonIndex < springBootIndex, + "Without the Spring Boot parent POM, the explicit Jackson override BOM must precede spring-boot-dependencies" + ); + } + + /** Finds the repository root from root- or module-scoped Maven execution. */ + private static Path projectRoot() { + Path current = Paths.get(System.getProperty("user.dir")).toAbsolutePath(); + Path lastPomParent = null; + while (current != null) { + if (Files.exists(current.resolve(".git"))) { + return current; + } + if (Files.exists(current.resolve("pom.xml"))) { + lastPomParent = current; + } + current = current.getParent(); + } + if (lastPomParent != null) { + return lastPomParent; + } + throw new IllegalStateException("Could not find project root"); + } +} From 1e6a601e0e32770c629410d8f5b9623e3b6db39d Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Wed, 12 Aug 2026 06:17:28 +0900 Subject: [PATCH 2/2] fix(security): pin Jackson 2.21.5 LTS BOM --- pom.xml | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/pom.xml b/pom.xml index 7c0ee7c2..ef5b70f1 100644 --- a/pom.xml +++ b/pom.xml @@ -23,6 +23,7 @@ 25 3.5.16 2025.0.3 + 2.21.5 42.7.12 3.3.16 2.0.13 @@ -33,6 +34,18 @@ + + + com.fasterxml.jackson + jackson-bom + ${jackson-bom.version} + pom + import + org.springframework.boot spring-boot-dependencies