See <https://ci-builds.apache.org/job/Struts/job/Struts-examples-dependency-check/107/display/redirect?page=changes>
Changes: [github] Bump shiro.version from 1.12.0 to 1.13.0 [github] Bump org.apache.maven.plugins:maven-failsafe-plugin from 3.2.1 to 3.2.2 [github] Bump org.springframework:spring-web from 5.3.23 to 6.1.1 [github] Bump actions/setup-java from 3 to 4 [github] Bump io.quarkus:quarkus-universe-bom from 3.5.0 to 3.6.0 [github] Bump org.apache.maven.plugins:maven-javadoc-plugin from 3.6.0 to 3.6.3 [github] Bump org.apache.struts:struts2-core from 6.3.0.1 to 6.3.0.2 [github] Bump io.quarkus:quarkus-universe-bom from 3.6.0 to 3.6.1 [github] Bump net.sf.jasperreports:jasperreports from 6.20.6 to 6.21.0 [github] Bump log4j2.version from 2.21.1 to 2.22.0 [aopenasus] Fix freemarker template error in `themes` example ------------------------------------------ [...truncated 62.95 KB...] at org.apache.maven.lifecycle.internal.LifecycleModuleBuilder.buildProject (LifecycleModuleBuilder.java:117) at org.apache.maven.lifecycle.internal.LifecycleModuleBuilder.buildProject (LifecycleModuleBuilder.java:81) at org.apache.maven.lifecycle.internal.builder.singlethreaded.SingleThreadedBuilder.build (SingleThreadedBuilder.java:56) at org.apache.maven.lifecycle.internal.LifecycleStarter.execute (LifecycleStarter.java:128) at org.apache.maven.DefaultMaven.doExecute (DefaultMaven.java:305) at org.apache.maven.DefaultMaven.doExecute (DefaultMaven.java:192) at org.apache.maven.DefaultMaven.execute (DefaultMaven.java:105) at org.apache.maven.cli.MavenCli.execute (MavenCli.java:956) at org.apache.maven.cli.MavenCli.doMain (MavenCli.java:290) at org.apache.maven.cli.MavenCli.main (MavenCli.java:194) at jdk.internal.reflect.NativeMethodAccessorImpl.invoke0 (Native Method) at jdk.internal.reflect.NativeMethodAccessorImpl.invoke (NativeMethodAccessorImpl.java:62) at jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke (DelegatingMethodAccessorImpl.java:43) at java.lang.reflect.Method.invoke (Method.java:566) at org.codehaus.plexus.classworlds.launcher.Launcher.launchEnhanced (Launcher.java:289) at org.codehaus.plexus.classworlds.launcher.Launcher.launch (Launcher.java:229) at org.codehaus.plexus.classworlds.launcher.Launcher.mainWithExitCode (Launcher.java:415) at org.codehaus.plexus.classworlds.launcher.Launcher.main (Launcher.java:356) at jdk.internal.reflect.NativeMethodAccessorImpl.invoke0 (Native Method) at jdk.internal.reflect.NativeMethodAccessorImpl.invoke (NativeMethodAccessorImpl.java:62) at jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke (DelegatingMethodAccessorImpl.java:43) at java.lang.reflect.Method.invoke (Method.java:566) at org.apache.maven.wrapper.BootstrapMainStarter.start (BootstrapMainStarter.java:39) at org.apache.maven.wrapper.WrapperExecutor.execute (WrapperExecutor.java:122) at org.apache.maven.wrapper.MavenWrapperMain.main (MavenWrapperMain.java:55) [INFO] Checking for updates [INFO] NVD CVE requires several updates; this could take a couple of minutes. [INFO] Download Started for NVD CVE - 2002 [INFO] Download Complete for NVD CVE - 2002 (905 ms) [INFO] Processing Started for NVD CVE - 2002 WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.fasterxml.jackson.module.afterburner.util.MyClassLoader (file:/home/jenkins/.m2/repository/com/fasterxml/jackson/module/jackson-module-afterburner/2.13.4/jackson-module-afterburner-2.13.4.jar) to method java.lang.ClassLoader.findLoadedClass(java.lang.String) WARNING: Please consider reporting this to the maintainers of com.fasterxml.jackson.module.afterburner.util.MyClassLoader WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release [INFO] Download Started for NVD CVE - 2004 [INFO] Download Complete for NVD CVE - 2004 (614 ms) [INFO] Processing Started for NVD CVE - 2004 [INFO] Download Started for NVD CVE - 2005 [INFO] Download Complete for NVD CVE - 2005 (686 ms) [INFO] Processing Started for NVD CVE - 2005 [INFO] Processing Complete for NVD CVE - 2004 (7633 ms) [INFO] Download Started for NVD CVE - 2006 [INFO] Processing Complete for NVD CVE - 2002 (13511 ms) [INFO] Download Complete for NVD CVE - 2006 (710 ms) [INFO] Processing Started for NVD CVE - 2006 [INFO] Download Started for NVD CVE - 2007 [INFO] Download Complete for NVD CVE - 2007 (720 ms) [INFO] Processing Started for NVD CVE - 2007 [INFO] Processing Complete for NVD CVE - 2005 (9914 ms) [INFO] Download Started for NVD CVE - 2008 [INFO] Download Complete for NVD CVE - 2008 (710 ms) [INFO] Processing Started for NVD CVE - 2008 [INFO] Download Started for NVD CVE - 2009 [INFO] Download Complete for NVD CVE - 2009 (694 ms) [INFO] Processing Started for NVD CVE - 2009 [INFO] Processing Complete for NVD CVE - 2006 (16250 ms) [INFO] Download Started for NVD CVE - 2010 [INFO] Download Complete for NVD CVE - 2010 (690 ms) [INFO] Processing Started for NVD CVE - 2010 [INFO] Processing Complete for NVD CVE - 2007 (14726 ms) [INFO] Download Started for NVD CVE - 2011 [INFO] Download Complete for NVD CVE - 2011 (716 ms) [INFO] Processing Started for NVD CVE - 2011 [INFO] Download Started for NVD CVE - 2012 [INFO] Download Complete for NVD CVE - 2012 (710 ms) [INFO] Processing Started for NVD CVE - 2012 [INFO] Processing Complete for NVD CVE - 2008 (19565 ms) [INFO] Download Started for NVD CVE - 2013 [INFO] Processing Complete for NVD CVE - 2009 (18483 ms) [INFO] Download Complete for NVD CVE - 2013 (728 ms) [INFO] Processing Started for NVD CVE - 2013 [INFO] Download Started for NVD CVE - 2014 [INFO] Download Complete for NVD CVE - 2014 (705 ms) [INFO] Processing Started for NVD CVE - 2014 [INFO] Download Started for NVD CVE - 2015 [INFO] Processing Complete for NVD CVE - 2010 (23572 ms) [INFO] Download Complete for NVD CVE - 2015 (686 ms) [INFO] Processing Started for NVD CVE - 2015 [INFO] Download Started for NVD CVE - 2016 [INFO] Download Complete for NVD CVE - 2016 (711 ms) [INFO] Processing Started for NVD CVE - 2016 [INFO] Processing Complete for NVD CVE - 2011 (27479 ms) [INFO] Download Started for NVD CVE - 2017 [INFO] Download Complete for NVD CVE - 2017 (784 ms) [INFO] Processing Started for NVD CVE - 2017 [INFO] Download Started for NVD CVE - 2018 [INFO] Download Complete for NVD CVE - 2018 (778 ms) [INFO] Processing Started for NVD CVE - 2018 [INFO] Download Started for NVD CVE - 2019 [INFO] Download Complete for NVD CVE - 2019 (773 ms) [INFO] Processing Started for NVD CVE - 2019 [INFO] Processing Complete for NVD CVE - 2014 (27710 ms) [INFO] Download Started for NVD CVE - 2020 [INFO] Processing Complete for NVD CVE - 2012 (37739 ms) [INFO] Download Complete for NVD CVE - 2020 (816 ms) [INFO] Processing Started for NVD CVE - 2020 [INFO] Processing Complete for NVD CVE - 2015 (24859 ms) [INFO] Processing Complete for NVD CVE - 2013 (36235 ms) [INFO] Download Started for NVD CVE - 2021 [INFO] Download Complete for NVD CVE - 2021 (850 ms) [INFO] Processing Started for NVD CVE - 2021 [INFO] Download Started for NVD CVE - 2022 [INFO] Processing Complete for NVD CVE - 2016 (28443 ms) [INFO] Download Complete for NVD CVE - 2022 (804 ms) [INFO] Processing Started for NVD CVE - 2022 [INFO] Download Started for NVD CVE - 2023 [INFO] Download Complete for NVD CVE - 2023 (813 ms) [INFO] Processing Started for NVD CVE - 2023 [INFO] Processing Complete for NVD CVE - 2018 (26754 ms) [INFO] Processing Complete for NVD CVE - 2017 (32514 ms) [INFO] Processing Complete for NVD CVE - 2019 (26311 ms) [INFO] Processing Complete for NVD CVE - 2020 (32546 ms) [INFO] Processing Complete for NVD CVE - 2021 (36242 ms) [INFO] Processing Complete for NVD CVE - 2023 (32754 ms) [INFO] Processing Complete for NVD CVE - 2022 (37637 ms) [INFO] Download Started for NVD CVE - Modified [INFO] Download Complete for NVD CVE - Modified (584 ms) [INFO] Processing Started for NVD CVE - Modified [INFO] Processing Complete for NVD CVE - Modified (2678 ms) [INFO] Begin database maintenance [INFO] Updated the CPE ecosystem on 132338 NVD records [INFO] Removed the CPE ecosystem on 334 NVD records [INFO] Cleaned up 335 orphaned NVD records [INFO] End database maintenance (25504 ms) [WARNING] A new version of dependency-check is available. Consider updating to version 9.0.7. [INFO] Begin database defrag [INFO] End database defrag (12545 ms) [INFO] Check for updates complete (273503 ms) [INFO] Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report. About ODC: https://jeremylong.github.io/DependencyCheck/general/internals.html False Positives: https://jeremylong.github.io/DependencyCheck/general/suppression.html 💖 Sponsor: https://github.com/sponsors/jeremylong [INFO] Analysis Started [INFO] Finished Archive Analyzer (0 seconds) [INFO] Finished File Name Analyzer (0 seconds) [INFO] Finished Jar Analyzer (0 seconds) [INFO] Finished Dependency Merging Analyzer (0 seconds) [INFO] Finished Version Filter Analyzer (0 seconds) [INFO] Finished Hint Analyzer (0 seconds) [INFO] Created CPE Index (3 seconds) [INFO] Finished CPE Analyzer (4 seconds) [INFO] Finished False Positive Analyzer (0 seconds) [INFO] Finished NVD CVE Analyzer (0 seconds) [INFO] Finished RetireJS Analyzer (0 seconds) [INFO] Finished Sonatype OSS Index Analyzer (1 seconds) [INFO] Finished Vulnerability Suppression Analyzer (0 seconds) [INFO] Finished Dependency Bundling Analyzer (0 seconds) [INFO] Analysis Complete (6 seconds) [INFO] Writing report to: <https://ci-builds.apache.org/job/Struts/job/Struts-examples-dependency-check/ws/target/dependency-check-report.html> [WARNING] One or more dependencies were identified with known vulnerabilities in Struts 2 Examples: commons-fileupload-1.5.jar (pkg:maven/commons-fileupload/commons-fileupload@1.5, cpe:2.3:a:apache:commons_fileupload:1.5:*:*:*:*:*:*:*, cpe:2.3:a:apache:commons_net:1.5:*:*:*:*:*:*:*) : CVE-2021-37533 commons-io-2.13.0.jar (pkg:maven/commons-io/commons-io@2.13.0, cpe:2.3:a:apache:commons_io:2.13.0:*:*:*:*:*:*:*, cpe:2.3:a:apache:commons_net:2.13.0:*:*:*:*:*:*:*) : CVE-2021-37533 commons-text-1.10.0.jar (pkg:maven/org.apache.commons/commons-text@1.10.0, cpe:2.3:a:apache:commons_net:1.10.0:*:*:*:*:*:*:*, cpe:2.3:a:apache:commons_text:1.10.0:*:*:*:*:*:*:*) : CVE-2021-37533 See the dependency-check report for more details. [INFO] [INFO] -----------------< org.apache.struts:action-chaining >------------------ [INFO] Building Action chaining 1.1.0 [2/47] [INFO] --------------------------------[ war ]--------------------------------- [INFO] [INFO] --- maven-resources-plugin:2.6:resources (default-resources) @ action-chaining --- [INFO] Using 'UTF-8' encoding to copy filtered resources. [INFO] Copying 1 resource [INFO] [INFO] --- maven-compiler-plugin:3.1:compile (default-compile) @ action-chaining --- [INFO] Changes detected - recompiling the module! [INFO] Compiling 2 source files to <https://ci-builds.apache.org/job/Struts/job/Struts-examples-dependency-check/ws/action-chaining/target/classes> [INFO] ------------------------------------------------------------------------ [INFO] Reactor Summary: [INFO] [INFO] Struts 2 Examples 1.1.0 ............................ SUCCESS [04:51 min] [INFO] Action chaining .................................... FAILURE [ 0.835 s] [INFO] Annotations with Convention Plugin ................. SKIPPED [INFO] Basic Struts2 Example .............................. SKIPPED [INFO] Bean Validation .................................... SKIPPED [INFO] Struts 2 Blank Webapp .............................. SKIPPED [INFO] Coding Struts 2 Action ............................. SKIPPED [INFO] Control Tags ....................................... SKIPPED [INFO] CRUD Example ....................................... SKIPPED [INFO] Debugging Struts ................................... SKIPPED [INFO] Dynamic Url ........................................ SKIPPED [INFO] Exception handling ................................. SKIPPED [INFO] Exclude Parameters ................................. SKIPPED [INFO] Expression Cache ................................... SKIPPED [INFO] File upload ........................................ SKIPPED [INFO] Form Processing .................................... SKIPPED [INFO] Form Tags .......................................... SKIPPED [INFO] Form validation .................................... SKIPPED [INFO] XML based form validation .......................... SKIPPED [INFO] Hello World Struts 2 Example Application ........... SKIPPED [INFO] Http Session ....................................... SKIPPED [INFO] Struts 2 Interceptors .............................. SKIPPED [INFO] jfreechart ......................................... SKIPPED [INFO] JSON produce/consume ............................... SKIPPED [INFO] Customized JSON produce ............................ SKIPPED [INFO] Struts 2 Mail Reader Webapp ........................ SKIPPED [INFO] Message resource ................................... SKIPPED [INFO] Message Store ...................................... SKIPPED [INFO] Portlet Webapp ..................................... SKIPPED [INFO] Preparable Interface ............................... SKIPPED [INFO] Struts 2 Quarkus ................................... SKIPPED [INFO] REST to Action Mapper Example Application .......... SKIPPED [INFO] REST Plugin based application with AngularJS ....... SKIPPED [INFO] Struts2 with Basic Shiro Security Integration ...... SKIPPED [INFO] Struts2 with Spring Integration .................... SKIPPED [INFO] Custom TextProvider ................................ SKIPPED [INFO] Struts Tiles Example ............................... SKIPPED [INFO] Struts 2 Themes .................................... SKIPPED [INFO] Struts 2 Themes Override ........................... SKIPPED [INFO] Type Conversion .................................... SKIPPED [INFO] Unit Testing ....................................... SKIPPED [INFO] Unknown handler .................................... SKIPPED [INFO] Using Struts 2 Tags ................................ SKIPPED [INFO] validation-messages ................................ SKIPPED [INFO] Wildcard Method Selection .......................... SKIPPED [INFO] Wildcard RegEx pattern matching .................... SKIPPED [INFO] JasperReports Tutorial 1.1.0 ....................... SKIPPED [INFO] ------------------------------------------------------------------------ [INFO] BUILD FAILURE [INFO] ------------------------------------------------------------------------ [INFO] Total time: 04:56 min [INFO] Finished at: 2023-12-29T22:04:09Z [INFO] ------------------------------------------------------------------------ [ERROR] Failed to execute goal org.apache.maven.plugins:maven-compiler-plugin:3.1:compile (default-compile) on project action-chaining: Fatal error compiling: error: invalid target release: 17 -> [Help 1] [ERROR] [ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch. [ERROR] Re-run Maven using the -X switch to enable full debug logging. [ERROR] [ERROR] For more information about the errors and possible solutions, please read the following articles: [ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/MojoExecutionException [ERROR] [ERROR] After correcting the problems, you can resume the build with the command [ERROR] mvn <goals> -rf :action-chaining Build step 'Execute shell' marked build as failure ERROR: No tool found matching MAVEN_3_LATEST__HOME