mirror of https://github.com/OpenIdentityPlatform/OpenDJ.git

Valery Kharseko
10 hours ago 58666fd764de42df1615625ea5623dcc1a1a6e15
refs
author Valery Kharseko <vharseko@3a-systems.ru>
Tuesday, October 6, 2026 13:34 +0200
committer GitHub <noreply@github.com>
Tuesday, October 6, 2026 13:34 +0200
commit58666fd764de42df1615625ea5623dcc1a1a6e15
tree b2bc08f47b0d0ed74fb765f190765c070f8227c1 tree | zip | gz
parent 60be91d8768178e3c4bbd8f01b713be382b9e9cf view | diff
Bump FreeMarker to 2.3.35 and fix the loadObjectClassesToMaps javadoc (#1176)

Two code scanning alerts on `master`.

### Alert 1297: FreeMarker 2.3.34 → 2.3.35 (CVE-2026-84939)

FreeMarker before 2.3.35 resolves a malformed locale identifier into a
path outside the template root. Trivy reports it on
`opt/opendj/lib/org.freemarker.freemarker.jar` of the image built from
`master` (`trivy-build-alpine`).

In OpenDJ it is not reachable: FreeMarker only renders OpenDJ's own
templates, in `DocGenerationHelper` (opendj-cli) and the doc maven
plugin, and nothing takes a locale from a client. The jar ships in
`lib/` all the same, so the alert stays open until the version moves.
commons made the same bump in OpenIdentityPlatform/commons#311.

All three `Configuration` instances are built with
`Configuration.DEFAULT_INCOMPATIBLE_IMPROVEMENTS`, a fixed constant, so
the template behaviour does not follow the library version.

### Alert 1281: `CompressedSchema.loadObjectClassesToMaps` javadoc

The javadoc listed a `sync` parameter the method does not have (left
over from #920) and documented `mappings` twice, with the encode and
decode maps the wrong way round.

### Not in this PR

- jackson 2.18.9 → 2.18.11 (alerts 1302, 1305–1308) and netty-handler
4.2.15 → 4.2.17+ (alert 1284) come from the commons parent
(`jackson.version`, `netty-bom`), so they belong in a commons change and
a `commons.version` bump.
- The `trivy-image-*` alerts are on the published 5.1.2 image; `master`
already carries the fixed versions (bc-fips 2.1.3, jackson 2.18.9,
postgresql 42.7.12, mssql-jdbc 13.4.0, a fresh base image). They close
with the next release.

### Testing

`mvn -pl opendj-cli,opendj-doc-maven-plugin -am package -DskipTests`
builds with 2.3.35. The documentation generation itself runs in CI.
2 files modified
9 ■■■■■ changed files
opendj-server-legacy/src/main/java/org/opends/server/api/CompressedSchema.java 7 ●●●●● diff | view | raw | blame | history
pom.xml 2 ●●●●● diff | view | raw | blame | history