Skip to content

Bump Gson 2.8.5 to 2.14.0 and drop the deprecated JsonParser instances - #64

Open
lgnap wants to merge 1 commit into
antoinevalentinHA:masterfrom
lgnap:chore/issue-19-gson-bump
Open

lgnap wants to merge 1 commit into
antoinevalentinHA:masterfrom
lgnap:chore/issue-19-gson-bump

Conversation

@lgnap

@lgnap lgnap commented Sep 11, 2026

Copy link
Copy Markdown

What

pom.xml pinned Gson 2.8.5 (2018), which carries CVE-2022-25647 (deserialization DoS, fixed in 2.8.9). The single managed version moves to the current 2.14.0; no module overrides it. Usage across core, metadata, agent and web-ui is plain parsing and serialization — nothing reflective on JDK internals, which is where Gson ≥ 2.10 got stricter — and the whole suite passes unchanged on the bump alone.

Since the bump makes new JsonParser().parse(reader) (deprecated since 2.8.6) visible, the eight call sites in ArchiveStoryPackReader and DatabaseMetadataService move to the static JsonParser.parseReader(...). A rename, not a behaviour change; the core round-trip tests and the metadata tests cover every one of them.

agent shades Gson into its jar-with-dependencies; it now ships 2.14.0 too.

Locally: mvn -B -Dskip.installnodeyarn=true -Dskip.yarn=true test → 330 run, 0 failures (39 FAT32 opt-in skips). git diff --exit-code clean.

Tracked in lgnap#19, extracted from #3.

🤖 Generated with Claude Code

…nstances

2.8.5 is from 2018 and carries CVE-2022-25647 (deserialization DoS,
fixed in 2.8.9). The managed version moves to the current release; no
module overrides it. Usage is plain parsing and serialization, and the
whole suite passes unchanged.

The instance API `new JsonParser().parse(reader)` has been deprecated
since 2.8.6 in favour of the static `JsonParser.parseReader`; the eight
call sites in core and metadata move over, which is a rename, not a
behaviour change — the round-trip and metadata tests cover them.

Closes #19

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant