Skip to content

fix(deps): update dependency com.sun.mail:jakarta.mail to v1.6.8 [security] - #3

Open
renovate[bot] wants to merge 3 commits into
mainfrom
renovate/maven-com.sun.mail-jakarta.mail-vulnerability
Open

renovate[bot] wants to merge 3 commits into
mainfrom
renovate/maven-com.sun.mail-jakarta.mail-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Jul 21, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Confidence
com.sun.mail:jakarta.mail (source) 1.6.71.6.8 age confidence

Jakarta Mail vulnerable to SMTP Injection

CVE-2025-7962 / GHSA-9342-92gg-6v29

More information

Details

In Jakarta Mail 2.2 it is possible to preform a SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.

Severity

  • CVSS Score: 6.0 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

eclipse-ee4j/mail (com.sun.mail:jakarta.mail)

v1.6.8

Compare Source


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

jonbartels and others added 3 commits July 20, 2026 22:02
Configure Renovate for dependency updates instead of Dependabot: monthly
schedule, 2-day minimumReleaseAge, coherent-project grouping (keyed deep
so unrelated org.apache.* projects stay separate), ecosystem labels, PR
limit, and OSV vulnerability alerts.

Because this repo enforces Gradle dependency verification and the metadata
file cannot always be regenerated by the bot, add a split-privilege
workflow that regenerates gradle/verification-metadata.xml on renovate/**
branches: an untrusted build job with a read-only token and no secrets
produces the file, and a separate trusted job that runs no dependency code
commits it. This isolates the writable token from untrusted execution.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Jon Bartels <jonathan.bartels@gmail.com>
Add Renovate config (Gradle + Docker) + metadata regen workflow
@github-actions

Copy link
Copy Markdown

Test Results

654 tests  ±0   654 ✅ ±0   3m 22s ⏱️ +26s
108 suites ±0     0 💤 ±0 
108 files   ±0     0 ❌ ±0 

Results for commit 509baf4. ± Comparison against base commit 0f5d74b.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant