1. c8af5c0 Merge pull request #230 from epugh/fix-regen-shaded-guava by Eric Pugh · 11 days ago main
  2. 05b33dd rebuilt dependencies plus enhance script. by Eric Pugh · 11 days ago
  3. e329183 Fix regenerator: don't count a repackaged jar's embedded Maven metadata as the artifact by Eric Pugh · 11 days ago
  4. fb48899 Merge pull request #229 from epugh/SOLR-17825-beanutils-range by Eric Pugh · 12 days ago
  5. 73b3893 Cap CVE-2025-48734 (commons-beanutils) range at 9.10.1/10.0.0 (fixed in 9.11/10.1) by Eric Pugh · 12 days ago
  6. d9452fe Merge pull request #223 from epugh/SOLR-10702 by Eric Pugh · 12 days ago
  7. e2e945c Merge pull request #228 from epugh/SOLR-18013-lz4-vex by Eric Pugh · 12 days ago
  8. 1034b61 Split lz4-java CVEs by fix boundary; emit real org.lz4 purl by Eric Pugh · 12 days ago
  9. c36e834 Merge pull request #220 from epugh/SOLR-18013 by Eric Pugh · 12 days ago
  10. e5ad2f7 Merge pull request #221 from epugh/SOLR-16309 by Eric Pugh · 12 days ago
  11. 54850f4 Merge pull request #227 from epugh/split-jackson-2026-cves by Eric Pugh · 12 days ago
  12. bb6759e Split bundled 2026 jackson-databind VEX entry into per-CVE files with accurate ranges by Eric Pugh · 12 days ago
  13. 487c757 Merge pull request #219 from epugh/SOLR-18333 by Eric Pugh · 12 days ago
  14. 755853a Merge pull request #226 from epugh/refine-jackson-gadget-cve-range by Eric Pugh · 12 days ago
  15. 3be4282 Refine jackson-databind gadget CVE range to 4.7.0-8.6.3 by Eric Pugh · 12 days ago
  16. 51003dc Merge pull request #218 from epugh/SOLR-17236 by Eric Pugh · 12 days ago
  17. 028f626 Merge pull request #225 from epugh/SOLR-15507-thrift-range by Eric Pugh · 12 days ago
  18. 0892a5a Correct CVE-2020-13949 (thrift) affected range to 8.2.0-8.11.0 by Eric Pugh · 12 days ago
  19. 80f04a5 Merge pull request #222 from epugh/SOLR-15507 by Eric Pugh · 12 days ago
  20. dd7b2f1 Merge pull request #224 from epugh/SOLR-17900-narrow-ranges by Eric Pugh · 12 days ago
  21. 8f50c78 Dug back in, and yeah, it was too broad. by Eric Pugh · 12 days ago
  22. 990c7a0 Merge pull request #216 from epugh/SOLR-17900 by Eric Pugh · 12 days ago
  23. 1b587c5 Merge pull request #217 from epugh/vex-openvex-per-cve-statements by Eric Pugh · 12 days ago
  24. 559bf77 Merge pull request #215 from epugh/SOLR-17899 by Eric Pugh · 12 days ago
  25. 36dd34c Merge pull request #214 from epugh/SOLR-17901 by Eric Pugh · 12 days ago
  26. 74b6fd0 Merge pull request #212 from epugh/SOLR-17903-poi-cve by Eric Pugh · 13 days ago
  27. 311e206 Document that in 9.0 and 9.1 we had exploitable CVE by Eric Pugh · 13 days ago
  28. 4a8b0a0 docuemnt that this was fixed "back in the day" by Eric Pugh · 14 days ago
  29. c15f7ca document the jquery-ui CVE applicablity. by Eric Pugh · 14 days ago
  30. 3e9a8be Expand existing file with additional CVES by Eric Pugh · 14 days ago
  31. f888daa Document the CVE, it's already partly covered in this existing file by Eric Pugh · 14 days ago
  32. 9f1ba6a Expand the details to link to a Solr JIRA that highlights the same issue. by Eric Pugh · 14 days ago
  33. 6ca22d4 Enhance OpenVEX generator so that aliases are expanded into the one statement per id for suppression by Eric Pugh · 14 days ago
  34. f1cc11a Hadoop client CVEs, expand on one existing, add four new ones. SOLR-17900 by Eric Pugh · 14 days ago
  35. 09cedf1 Document the impact of these cves on Solr by Eric Pugh · 14 days ago
  36. 9e5e489 Document that solr is not vulnerable to CVE-2024-21742 apache-mimej-core by Eric Pugh · 14 days ago
  37. fbf7980 Merge remote-tracking branch 'upstream/main' into SOLR-17903-poi-cve by Eric Pugh · 14 days ago
  38. 7557fdd Merge pull request #213 from epugh/sort-vex-dependency-versions by Eric Pugh · 14 days ago
  39. 80f3dc9 reduce churn in this file by making sure keys are sorted properly as we add new information. by Eric Pugh · 14 days ago
  40. 7004966 Describe why this CVE is not an issue for Solr by Eric Pugh · 14 days ago
  41. 175c0d9 Merge pull request #211 from epugh/reviewing_remaining_cves by Eric Pugh · 14 days ago
  42. 00c9d74 Refine the OpenNLP ranges as these are fixed by Eric Pugh · 14 days ago
  43. 2918942 Add vex statement that moves from in_triage to not_affected. by Eric Pugh · 14 days ago
  44. 10ace04 Add remaining statements that cover current 9.11 and 10.1 snapshot docker image builds. by Eric Pugh · 14 days ago
  45. 809adea Merge pull request #198 from apache/dependabot/docker/python-2673086 by Jan Høydahl · 3 weeks ago
  46. a28d3b1 Merge pull request #209 from apache/dependabot/github_actions/actions/checkout-7.0.1 by Jan Høydahl · 3 weeks ago
  47. 9d1c5c5 Merge pull request #210 from apache/dependabot/pip/pip-tools-7.6.0 by Jan Høydahl · 3 weeks ago
  48. 7072ca6 Bump pip-tools from 7.5.3 to 7.6.0 by dependabot[bot] · 3 weeks ago
  49. 8bffc69 Bump actions/checkout from 7.0.0 to 7.0.1 by dependabot[bot] · 3 weeks ago
  50. 2e55084 Merge pull request #197 from apache/dependabot/github_actions/actions/checkout-7.0.0 by Eric Pugh · 4 weeks ago
  51. 0e3a2b3 Merge pull request #208 from apache/dependabot/pip/setuptools-83.0.0 by Eric Pugh · 4 weeks ago
  52. 91c0231 Merge pull request #173 from apache/Update-vex by Eric Pugh · 4 weeks ago
  53. d6ff765 Update dependencies napping for new jars. by Eric Pugh · 4 weeks ago Update-vex
  54. 9e6d39f Filter out shaded code that doesn't actually ship. It conflicts between our licenses listing and what syft finds and is a false positive. by Eric Pugh · 4 weeks ago
  55. defafdc Convert older json content into our vex statement markdown. Expanded versions to be accurate. by Eric Pugh · 4 weeks ago
  56. 9f1690d Merge remote-tracking branch 'upstream/main' into Update-vex by Eric Pugh · 4 weeks ago
  57. 6bb7666 Merge pull request #204 from epugh/add_openvex_support by Eric Pugh · 4 weeks ago
  58. c37e54c Merge remote-tracking branch 'upstream/main' into Update-vex by Eric Pugh · 4 weeks ago
  59. cb01a37 Document the vex steps. by Eric Pugh · 4 weeks ago
  60. a49ddfd strip out the scanning of -slim version of solr, that doesn't help us at all! by Eric Pugh · 4 weeks ago
  61. 2e3ba6c Reduces future error of omission by building in updating this as part of regen fro solr 9 and later releases. Pre 9 is static. by Eric Pugh · 4 weeks ago
  62. b22617a Nicer variable name, be clear what we are doing. by Eric Pugh · 4 weeks ago
  63. 0c10098 Bump setuptools from 82.0.1 to 83.0.0 by dependabot[bot] · 4 weeks ago
  64. 194b79d Merge remote-tracking branch 'upstream/main' into add_openvex_support by Eric Pugh · 5 weeks ago
  65. 56554be Merge remote-tracking branch 'upstream/main' into add_openvex_support by Eric Pugh · 5 weeks ago
  66. 1752d80 Merge pull request #205 from epugh/add_lower_bounds_to_versions by Eric Pugh · 5 weeks ago
  67. 9180c4c Merge pull request #206 from epugh/add_netty_cves by Eric Pugh · 5 weeks ago
  68. 2301713 Demonstate using 'syft' tool to generate sbom that populates the solr version mapping file. by Eric Pugh · 5 weeks ago
  69. 9fdcc3a modules: solr-core or solr-solrj support. Omitting means solr-core. by Eric Pugh · 5 weeks ago
  70. 55d1658 Eliminate hardcoded JAR_GROUPS by using the current generated file. by Eric Pugh · 5 weeks ago
  71. b636c0e Be more explicit about zk and ssl... by Eric Pugh · 5 weeks ago
  72. 511e2a7 Provide more detailed history of netty in Solr, looking back at the netty-all uber jar. by Eric Pugh · 5 weeks ago
  73. 358e841 as part of adding more netty cves, we added more of these mappings. Ugh. by Eric Pugh · 5 weeks ago
  74. 870c9e3 Document Netty CVE's impact on Solr by Eric Pugh · 5 weeks ago
  75. 481d358 Document how to use vex files with docker scout command. by Eric Pugh · 5 weeks ago
  76. d8b2ecc Openvex file being generated, though with hardcoded mappings. by Eric Pugh · 5 weeks ago
  77. 6d315d9 Refine the VEX files to have specific jars and specific begin/end versions. by Eric Pugh · 5 weeks ago
  78. 8257a48 Merge pull request #199 from apache/dependabot/pip/beautifulsoup4-4.15.0 by Eric Pugh · 6 weeks ago
  79. 823a703 Merge pull request #202 from apache/dependabot/pip/pip-26.1.2 by Eric Pugh · 6 weeks ago
  80. 1369d33 Merge pull request #203 from apache/dependabot/pip/soupsieve-2.8.4 by Eric Pugh · 6 weeks ago
  81. a463d3b List out each version of Solr that a VEX statement applies to. Only works with lower bounded statements. by Eric Pugh · 6 weeks ago
  82. 64f0f83 Generate openvex from our cyclonedx inspired vex files. by Eric Pugh · 6 weeks ago
  83. 112478f Merge pull request #200 from epugh/cves_in_jetty_10 by Eric Pugh · 6 weeks ago
  84. 5e06326 Bump soupsieve from 2.8.3 to 2.8.4 by dependabot[bot] · 7 weeks ago
  85. dfb8968 Bump pip from 26.1 to 26.1.2 by dependabot[bot] · 7 weeks ago
  86. d68c862 the way to mitifate this bug is at the proxy layer by Eric Pugh · 8 weeks ago
  87. d4f1753 We require that vulnerabilties be exploitable against a secure Solr setup, and so this issue can be marked not exploitable when you have secure solr by Eric Pugh · 8 weeks ago
  88. 08df1df VEX statements for CVEs affecting Jetty 10 in Solr 9 by Eric Pugh · 8 weeks ago
  89. 1d00046 Bump beautifulsoup4 from 4.14.3 to 4.15.0 by dependabot[bot] · 8 weeks ago
  90. 9b0554c Bump python from `5a824eb` to `2673086` by dependabot[bot] · 8 weeks ago
  91. 368b19e Bump actions/checkout from 6.0.3 to 7.0.0 by dependabot[bot] · 8 weeks ago
  92. 127ea72 Add docs button to menus and fix operator docs links (#190) by Houston Putman · 9 weeks ago
  93. 289d270 Merge pull request #196 from epugh/bump_cyclonedx_version_statement by Eric Pugh · 9 weeks ago
  94. 84841e7 bumped the version we are using by Eric Pugh · 9 weeks ago
  95. 634dd7e Merge pull request #152 from ppkarwasz/fix/CVE-2025-48924_commons-lang by Eric Pugh · 9 weeks ago
  96. aa91d0f Document commons lang vulnerablity by Eric Pugh · 9 weeks ago
  97. b5cc498 Merge remote-tracking branch 'upstream/main' into pr/152 by Eric Pugh · 9 weeks ago
  98. 282e8ad Merge pull request #194 from apache/dependabot/pip/tornado-6.5.7 by Eric Pugh · 9 weeks ago
  99. 2017b38 Merge pull request #191 from epugh/vex-table-list-all by Eric Pugh · 9 weeks ago
  100. 705f8dd Merge pull request #192 from epugh/add_opennlp_cve_as_vex by Eric Pugh · 9 weeks ago