Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Bump org.jline:jansi from 4.4.2 to 4.4.3 - #772

Merged
Lenni0451 merged 1 commit into
mainfrom
dependabot/gradle/org.jline-jansi-4.4.3
Sep 14, 2026
Merged

Bump org.jline:jansi from 4.4.2 to 4.4.3#772
Lenni0451 merged 1 commit into
mainfrom
dependabot/gradle/org.jline-jansi-4.4.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor

Bumps org.jline:jansi from 4.4.2 to 4.4.3.

Release notes

Sourced from org.jline:jansi's releases.

JLine 4.4.3 is a security patch release addressing multiple vulnerabilities reported by AFINE/CERT.PL, plus bug fixes and dependency updates.

🔒 Security Fixes

  • Native Stack Buffer Overflow in Public INPUT_RECORD.memmove JNI Method (Windows) (GHSA-6r3w-6jpj-x5w6)
  • Authenticated SSH Shell Channel Resource Leak via Null or Non-Numeric PTY Dimensions (GHSA-7h86-pjwh-gpqj)
  • Authenticated SSH DoS via Unbounded Window-Change Terminal Geometry (GHSA-m935-wqpj-pvp3)
  • TCP Socket File Descriptor Leak When Maximum Connections Reached (GHSA-c87g-867h-cqr6)

🐛 Bug Fixes

  • fix: verify server host keys in the ssh client builtin (#2236) @​uchiha-bug-hunter
  • fix: address remaining security vulnerabilities reported by AFINE/CERT.PL (#2235) @​gnodet
  • fix: use Release Drafter draft for GitHub release and fail closed on lookup errors (#2232) @​gnodet

📦 Dependency updates

Commits
  • 15f6fdd chore: bump org.graalvm.buildtools:native-maven-plugin (#2242)
  • f5366be chore: bump com.diffplug.spotless:spotless-maven-plugin (#2246)
  • 799a266 chore: bump groovy.version from 5.1.1 to 5.1.2 (#2245)
  • 19757c8 chore: bump slf4j.version from 2.0.18 to 2.0.19 (#2244)
  • 47e16bf fix: verify server host keys in the ssh client builtin (#2236)
  • ff4d59b chore: bump org.apache.maven.plugins:maven-surefire-plugin (#2234)
  • 0cb3afd fix: address remaining security vulnerabilities reported by AFINE/CERT.PL (#2...
  • 347b880 fix: use Release Drafter draft for GitHub release and fail closed on lookup e...
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.jline:jansi](https://github.com/jline/jline3) from 4.4.2 to 4.4.3.
- [Release notes](https://github.com/jline/jline3/releases)
- [Commits](jline/jline3@4.4.2...4.4.3)

---
updated-dependencies:
- dependency-name: org.jline:jansi
  dependency-version: 4.4.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Sep 14, 2026
@Lenni0451
Lenni0451 merged commit 97427d6 into main Sep 14, 2026
2 checks passed
@dependabot
dependabot Bot deleted the dependabot/gradle/org.jline-jansi-4.4.3 branch September 14, 2026 04:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant