SUSE-SU-2026:3390-1: important: Security update for apache-commons-lang3, google-guice, maven, maven-resolver, xmvn

SLE-SECURITY-UPDATES null at suse.de
Tue Jul 28 20:47:05 UTC 2026


# Security update for apache-commons-lang3, google-guice, maven, maven-resolver,
xmvn

Announcement ID: SUSE-SU-2026:3390-1  
Release Date: 2026-07-28T15:40:06Z  
Rating: important  
References:

  
Cross-References:

  * CVE-2025-48924

  
CVSS scores:

  * CVE-2025-48924 ( SUSE ):  5.7
    CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2025-48924 ( SUSE ):  4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
  * CVE-2025-48924 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

  
Affected Products:

  * Basesystem Module 15-SP7
  * Development Tools Module 15-SP7
  * SUSE Linux Enterprise Desktop 15 SP7
  * SUSE Linux Enterprise High Performance Computing 15 SP4
  * SUSE Linux Enterprise High Performance Computing 15 SP5
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
  * SUSE Linux Enterprise Real Time 15 SP7
  * SUSE Linux Enterprise Server 15 SP4
  * SUSE Linux Enterprise Server 15 SP4 LTSS
  * SUSE Linux Enterprise Server 15 SP5
  * SUSE Linux Enterprise Server 15 SP5 LTSS
  * SUSE Linux Enterprise Server 15 SP6
  * SUSE Linux Enterprise Server 15 SP6 LTSS
  * SUSE Linux Enterprise Server 15 SP7
  * SUSE Linux Enterprise Server for SAP Applications 15 SP4
  * SUSE Linux Enterprise Server for SAP Applications 15 SP5
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6
  * SUSE Linux Enterprise Server for SAP Applications 15 SP7

  
  
An update that solves one vulnerability can now be installed.

## Description:

This update for apache-commons-lang3, google-guice, maven, maven-resolver, xmvn
fixes the following issues:

apache-commons-lang3 was updated to 3.20.0:

  * New features:

    * Add SystemProperties.getPath(String, Supplier<Path>)
    * Add JavaVersion.JAVA_25
    * Add JavaVersion.JAVA_26
    * Add SystemUtils.IS_JAVA_25
    * Add SystemUtils.IS_JAVA_26
    * Add MutablePair.ofNonNull(Map.Entry)
    * Add TimedSemaphore.builder(), Builder, and deprecate constructors
    * LANG-1504: Adding labels and history to split StopWatch
  * Fixed Bugs:

    * Optimize ObjectToStringComparator.compare() method
    * [javadoc] Improve StringUtils Javadoc
    * Fix internal inverted logic in private isEnum() method and correct its usage in getFirstEnum()
    * Use accessors in ToStringStyle so subclasses can effectively override them
    * 'LocaleUtils.toLocale(String)' for a 2 letter country code now returns a value instead of throwing an 'IllegalArgumentException'
    * Fix typo in StringUtils.trunctate() IllegalArgumentException message and test assertion messages
    * Fix test fixture in ReflectionDiffBuilderTest.testTransientFieldDifference()
    * LANG-1789: NullPointerException when generating NoSuchMethodException in MethodUtils
    * LANG-1786: Map deprecated TimeZone short IDs and avoid JRE WARNINGs to the console
    * LANG-1792: TypeUtils.toString() skips angle brackets for Class type
    * Mention JDK 25 LTS as a tested version in the release notes
  * Changes:

    * Bump org.apache.commons:commons-parent from 88 to 92

Update to 3.19.0:

  * New features:
    * Add ArrayUtils.SOFT_MAX_ARRAY_LENGTH
    * Add SystemUtils.IS_OS_NETWARE
    * Add MethodUtils.getAccessibleMethod(Class, Method)
    * Add documentation to site for CVE-2025-48924 ClassUtils.getClass(...) can throw a StackOverflowError on very long inputs
    * Add StringUtils.indexOfAny(CharSequence, int, char...)
    * Add ConcurrentException.ConcurrentException(String)
    * Add DateUtils.toLocalDateTime(Date[, TimeZone])
    * Add DateUtils.toOffsetDateTime(Date[, TimeZone])
    * Add DateUtils.toZonedDateTime(Date[, TimeZone])
    * Add ByteConsumer
    * Add ByteSupplier
    * Add FailableByteConsumer
    * Add FailableByteSupplier
    * LANG-1784: Add Functions methods for null-safe mapping and chaining
    * LANG-1784: Add Failable methods for null-safe mapping and chaining
    * Add DoubleRange.fit(double)
    * Add IntegerRange.fit(int)
    * Add LongRange.fit(long)
    * Add DurationUtils.get(String, TemporalUnit, long)
    * Add DurationUtils.getMillis(String, long)
    * Add DurationUtils.getSeconds(String, long)
    * Add SystemProperties.getBoolean(Class, String, boolean)
    * Add SystemProperties.getInt(Class, String, int)
    * Add SystemProperties.getLong(Class, String, long)
  * Fixed Bugs:
    * LANG-1778: MethodUtils.getMatchingMethod() doesn't respect the hierarchy of methods
    * MethodUtils.getMethodObject(Class<?>, String, Class<?>...) now returns null instead of throwing a NullPointerException, as it does for other exception types
    * Reduce spurious failures in ArrayUtilsTest methods that test ArrayUtils.shuffle() methods
    * MethodUtils cannot find or invoke a public method on a public class implemented in its package-private superclass
    * AtomicSafeInitializer.get() can spin internally if the FailableSupplier given to AbstractConcurrentInitializer .AbstractBuilder.setInitializer(FailableSupplier) throws a RuntimeException
    * LANG-1783: WordUtils.containsAllWords?() may throw PatternSyntaxException
    * LANG-1782: MethodUtils cannot find or invoke vararg methods without providing vararg types or values
    * MethodUtils cannot find or invoke vararg methods of interface types
    * MethodUtils cannot find or invoke vararg methods when widening primitive types following the JLS 5.1.2. Widening Primitive Conversion
    * LANG-1597: Invocation fails because matching varargs method found but then discarded
    * Don't check accessibility twice in MemberUtils .setAccessibleWorkaround(T)
    * LANG-1774: Improve handling of ClassUtils .getShortCanonicalName() for invalid input
    * LANG-1720: Improve Javadocs for Conversion
    * Fix CalendarUtils.toLocalDate() Javadoc return type description
    * Fix the method name in Javadoc examples for CharUtils.isHex()
    * Deprecate NumberUtils.compare(byte, byte) in favor of Byte.compare(byte, byte)
    * Deprecate NumberUtils.compare(int, int) in favor of Integer.compare(int, int)
    * Deprecate NumberUtils.compare(long, long) in favor of Long.compare(long, long)
    * Deprecate NumberUtils.compare(short, short) in favor of Short.compare(short, short)
    * Deprecate obsolete system property constant SystemProperties.AWT_TOOLKIT
    * Deprecate obsolete system property constant SystemProperties.JAVA_AWT_FONTS
    * Deprecate obsolete system property constant SystemProperties.JAVA_AWT_GRAPHICSENV
    * Deprecate obsolete system property constant SystemProperties.JAVA_AWT_HEADLESS
    * Deprecate obsolete system property constant SystemProperties.JAVA_AWT_PRINTERJOB
    * Deprecate obsolete system property constant SystemProperties.JAVA_COMPILER
    * Deprecate obsolete system property constant SystemProperties.JAVA_ENDORSED_DIRS
    * Deprecate obsolete system property constant SystemProperties.JAVA_EXT_DIRS
    * Deprecate method for obsolete system property constant SystemProperties.getAwtToolkit()
    * Deprecate method for obsolete system property constant SystemProperties.getJavaAwtFonts()
    * Deprecate method for obsolete system property constant SystemProperties.getJavaAwtGraphicsenv()
    * Deprecate method for obsolete system property constant SystemProperties.getJavaAwtHeadless()
    * Deprecate method for obsolete system property constant SystemProperties.getJavaAwtPrinterjob()
    * Deprecate method for obsolete system property constant SystemProperties.getJavaCompiler()
    * Deprecate method for obsolete system property constant SystemProperties.getJavaEndorsedDirs()
    * Deprecate method for obsolete system property constant SystemProperties.getJavaExtDirs()
    * Deprecate method for obsolete system property constant SystemUtils.isJavaAwtHeadless()
    * Deprecate constants for obsolete system property SystemUtils.JAVA_AWT_FONTS
    * Deprecate constants for obsolete system property SystemUtils.JAVA_AWT_GRAPHICSENV
    * Deprecate constants for obsolete system property SystemUtils.JAVA_AWT_HEADLESS
    * Deprecate constants for obsolete system property SystemUtils.JAVA_AWT_PRINTERJOB
    * Deprecate constants for obsolete system property SystemUtils.JAVA_COMPILER
    * Deprecate constants for obsolete system property SystemUtils.JAVA_ENDORSED_DIRS
    * Deprecate constants for obsolete system property SystemUtils.JAVA_EXT_DIRS
    * [javadoc] General improvements
    * [javadoc] Fix thrown exception documentation for MethodUtils.getMethodObject(Class<?>, String, Class<?>...)
    * [javadoc] Strings::equalsAny: CI doc string should show it's insensitive
    * [javadoc] General Javadoc improvements
    * LANG-1780: [javadoc] Fix Strings Javadoc
    * [javadoc] Fix typo in Javadoc of Strings instances
    * [javadoc] Fix Javadocs in ClassUtils
    * [javadoc] Fix @deprecated link for StringUtils#startsWithAny
    * Replace old feather logotype with new oak logotype
  * Changes:
    * [test] Bump org.apache.commons:commons-text from 1.13.1 to 1.14.0
    * Bump org.apache.commons:commons-parent from 85 to 88

Update to 3.18.0:

  * Fix component version in default.properties to 3.12

    * Add and use LocaleUtils.toLocale(Locale) to avoid NPEs.
    * Add FailableShortSupplier, handy for JDBC APIs.
    * Add JavaVersion.JAVA_17.
    * Add StringUtils.substringBefore(String, int).
    * Add Range.INTEGER.
    * Add DurationUtils.
    * Correct implementation of RandomUtils.nextLong(long, long).
    * Update maven-surefire-plugin 2.22.2 -> 3.0.0-M5.
    * Bump junit-bom from 5.7.0 to 5.7.1.
    * Ignored exception 'ignored', should not be called so.
    * Change array style from 'int a[]' to 'int[] a'.

google-guice was updated to fix:

  * Fix build with Java 25
  * Add alias to com.google.inject:guice::classes artifact, needed by maven 4.x

maven-resolver-supplier was updated to upstream version 1.9.27:

  * Bug Fixes
    * Sync TrackingFileManager with 2.x

Update to upstream version 1.9.26:

  * New features and improvements
    * GH-1773: Treat 410 Gone as 404 Not Found
    * GH-1737: Revert partially parallel upload change
  * Bug Fixes
    * GH-1768; Drastically simplify auth caching
    * [1.9.x] Bug: GH-1703 Locally cached artifacts defy RRF
  * Documentation updates
    * Clarify that HTTP Transport uses Apache HTTP Client
  * Dependency updates

    * Bump org.redisson:redisson from 3.52.0 to 4.2.0
    * Bump commons-codec:commons-codec from 1.20.0 to 1.21.0
    * Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.26 to 1.27
    * Bump org.apache.maven:maven-parent from 46 to 47
    * Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.0 to 0.25.4
    * Bump mavenVersion from 3.9.11 to 3.9.12
  * Update to upstream version 1.9.25

  * New features and improvements
    * Add scope support for trusted checksums
    * Name mappers cleanup and new GAECV mapper
    * Proper metadata locking support
    * Ability to augment metadata nature for version range request
  * Bug Fixes
    * TrackingFileManager changes
    * Maven filters daemon friendly
    * Remove hack from Basic connector
    * Fix locking issues
  * Documentation updates
    * Updated the documentation to reflect the current list of name mappers
  * Maintenance
    * Mild backport: support same properties as Resolver 2.x
    * Maven resolver lockrepro
    * Bugfix: Java 25 broke test
  * Dependency updates

    * Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.23.1 to 0.25.0
    * Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.24 to 1.26
    * Bump commons-codec:commons-codec from 1.18.0 to 1.20.0
    * Bump org.redisson:redisson from 3.50.0 to 3.52.0
    * Bump com.google.guava:guava from 33.4.8-jre to 33.5.0-jre
    * Bump com.google.code.gson:gson from 2.13.1 to 2.13.2
    * Bump jettyVersion from 9.4.57.v20241219 to 9.4.58.v20250814
    * Bump mavenVersion from 3.9.10 to 3.9.11
  * Update to upstream version 1.9.24

  * New features and improvements
    * Metadata type out of coordinates
    * RFC9457 implementation
    * Intern context strings
  * Maintenance
    * Align plexus-util version with Maven
    * Align guice version with Maven
    * Enable Github Issues (1.9.x branch)
  * Build also maven-resolver-supplier package in separate spec file

  * Add dependency on objectweb-asm to build with sisu 0.9.0.M4

  * Update to upstream version 1.9.23

  * Bug
    * MRESOLVER-659: NPE in trusted checksum post processor if
  * Improvement

    * MRESOLVER-680: Disable checksum by default for .sigstore.json as well
    * MRESOLVER-703: HTTP transport should expose config for max redirects
  * Upgrade to upstream version 1.9.22

  * Bug
    * MRESOLVER-572: Resolver-Supplier unusable in OSGi runtimes
    * MRESOLVER-574: Invalid Cookie set under proxy conditions
    * MRESOLVER-586: In typical setups, DefaultArtifact copies the same maps over and over again
    * MRESOLVER-587: Memory consumption improvements
  * New Feature
    * MRESOLVER-571: Import o.e.aether packages with the exact same version in OSGi metadata
  * Improvement
    * MRESOLVER-570: Remove excessive strictness of OSGi dependency metadata
  * Task

    * MRESOLVER-576: Allow co-release of Resolver 1.x and 2.x
  * Upgrade to upstream version 1.9.20

  * Bug
    * MRESOLVER-483: PreorderNodeListGenerator bug: may print trailing ":"
    * MRESOLVER-522: File locking threads not entering critical region were "oversleeping"
    * MRESOLVER-547: BF collector always copies artifacts, even when it should not
  * Improvement

    * MRESOLVER-536: Skip setting last modified time when FS does not support it
  * Add dependency on plexus-xml where relevant

  * this will be needed for smooth upgrade to plexus-utils 4.0.0

  * Upgrade to upstream version 1.9.18

  * Bug
    * MRESOLVER-372: Sporadic AccessDeniedEx on Windows
    * MRESOLVER-441: Undo FileUtils changes that altered non-Windows execution path
  * Improvement
    * MRESOLVER-396: Native transport should retry on HTTP 429 (Retry-After)
  * Task

    * MRESOLVER-397: Deprecate Guice modules
    * MRESOLVER-405: Get rid of component name string literals, make them constants and reusable
    * MRESOLVER-433: Expose configuration for inhibiting Expect-Continue handshake in 1.x
    * MRESOLVER-435: Refresh download page
    * MRESOLVER-437: Resolver should not override given HTTP transport default use of expect-continue handshake
  * Upgrade to upstream version 1.9.15

  * Bug
    * MRESOLVER-373: Remove lock upgrading code
    * MRESOLVER-375: Several key aspects are broken in provided and trusted checksum feature
    * MRESOLVER-376: StackOverflowError at BfDependencyCollector.processDependency
    * MRESOLVER-380: Lock diagnostic: attempted lock step is recorded, but on failed attempt is not removed
    * MRESOLVER-393: Transport HTTP does not retain last modified as sent by remote end
  * Improvement
    * MRESOLVER-220: Modify signaling for unsupported operations
    * MRESOLVER-382: Define local outgoing (bind) address
    * MRESOLVER-385: Reduce default value for aether.connector.http.connectionMaxTtl
  * Task

    * MRESOLVER-378: Update parent POM to 40
    * MRESOLVER-381: Undo MRESOLVER-373 as it was fixed by other means
    * MRESOLVER-386: Make all injected ctors public, deprecate all def ctors
    * MRESOLVER-388: Transport HTTP old codec proper override
  * Upgrade to upstream version 1.9.12

  * Bug
    * [MRESOLVER-371] Unjustified WARNING log added by MRESOLVER-364
    * [MRESOLVER-361] Unreliable TCP and retries on upload
    * [MRESOLVER-357] ConflictResolver STANDARD verbosity misbehaves
    * [MRESOLVER-352] Duplicate METADATA_DOWNLOADING event is being sent
  * Improvement
    * [MRESOLVER-360] disable checksum by default for .sigstore in addition to .asc
  * New Feature
    * [MRESOLVER-370] Lock factory should dump lock states on failure
    * [MRESOLVER-353] Make aether.checksums.algorithms settable per remote repository
  * Task

    * [MRESOLVER-366] Upgrade build plugins
    * [MRESOLVER-364] Revert MRESOLVER-132
    * [MRESOLVER-359] Make build be explicit about build time requirements
    * [MRESOLVER-356] Remove Guava (is unused)
    * [MRESOLVER-354] Document expected checksums
  * Upgrade to upstream version 1.9.8

  * Bug
    * [MRESOLVER-345] Conflict resolution in verbose mode is sensitive to version ordering
    * [MRESOLVER-348] SslConfig httpSecurityMode change is not detected
    * [MRESOLVER-339] Preemptive Auth broken when default ports used
    * [MRESOLVER-325] [REGRESSION] Suddenly seeing I/O errors under windows aborting the build
    * [MRESOLVER-330] Static name mapper is unusable with file-lock factory
    * [MRESOLVER-314] Getting "IllegalArgumentException: Comparison method violates its general contract!"
    * [MRESOLVER-316] DF collector enters endless loop when collecting org.webjars.npm:musquette:1.1.1
    * [MRESOLVER-298] javax.inject should be provided or optional
    * [MRESOLVER-305] Evaluate blocked repositories also when retrieving metadata
    * [MRESOLVER-309] PrefixesRemoteRepositoryFilterSource aborts the build while it should not
    * [MRESOLVER-313] Artifact file permissions are 0600 and not implicitly set by umask
    * [MRESOLVER-296] FileProcessor.write( File, InputStream ) is defunct
    * [MRESOLVER-292] Documented and used param names mismatch
    * [MRESOLVER-294] Fix JapiCmp configuration and document it
    * [MRESOLVER-285] File locking on Windows knows to misbehave
    * [MRESOLVER-246] m-deploy-p will create hashes for hashes
    * [MRESOLVER-265] Discrepancy between produced and recognized checksums
    * [MRESOLVER-241] Resolver checksum calculation should be driven by layout
    * [MRESOLVER-242] When no remote checksums provided by layout, transfer inevitably fails/warns
    * [MRESOLVER-250] Usage of descriptors map in DataPool prevents gargabe collection
  * New Feature
    * [MRESOLVER-32] Support parallel artifact/metadata uploads
    * [MRESOLVER-319] Support parallel deploy
    * [MRESOLVER-297] Chained LRM
    * [MRESOLVER-167] Support forcing specific repositories for artifacts
    * [MRESOLVER-268] Apply artifact checksum verification for any resolved artifact
    * [MRESOLVER-274] Introduce Remote Repository Filter feature
    * [MRESOLVER-275] Introduce trusted checksums source
    * [MRESOLVER-276] Resolver post-processor
    * [MRESOLVER-278] BREAKING: Introduce RepositorySystem shutdown hooks
    * [MRESOLVER-236] Make it possible to resolve .asc on a 'fail' respository.
  * Improvement
    * [MRESOLVER-346] Too eager locking
    * [MRESOLVER-347] Better connection pool configuration (reuse, max TTL, maxPerRoute)
    * [MRESOLVER-349] Adapter when locking should "give up and retry"
    * [MRESOLVER-350] Get rid of commons-lang dependency
    * [MRESOLVER-327] Make tranport-http obey system properties regarding proxy settings
    * [MRESOLVER-340] Make WebDAV "dance" disabled by default
    * [MRESOLVER-341] Add option for preemptive PUT Auth
    * [MRESOLVER-315] Implement preemptive authentication feature for transport-http
    * [MRESOLVER-328] The transport-http should be able to ignore cert errors
    * [MRESOLVER-337] Real cause when artifact not found with repository filtering
    * [MRESOLVER-287] Get rid of deprecated finalize methods
    * [MRESOLVER-317] Improvements for BF collector
    * [MRESOLVER-318] Cleanup redundant code and centralize executor handling
    * [MRESOLVER-303] Make checksum detection reusable
    * [MRESOLVER-290] Improve file handling resolver wide
    * [MRESOLVER-7] Download dependency POMs in parallel in BF collector
    * [MRESOLVER-266] Simplify adapter creation and align configuration for it
    * [MRESOLVER-269] Allow more compact storage of provided checksums
    * [MRESOLVER-273] Create more compact File locking layout/mapper
    * [MRESOLVER-284] BREAKING: Some Sisu parameters needs to be bound
    * [MRESOLVER-286] Improve basic connector closed state handling
    * [MRESOLVER-240] Using breadth-first approach to resolve Maven dependencies
    * [MRESOLVER-247] Avoid unnecessary dependency resolution by a Skip solution based on BFS
    * [MRESOLVER-248] Make DF and BF collector implementations coexist
  * Task
    * [MRESOLVER-326] Resolver transport-http should retry on failures
    * [MRESOLVER-331] Make DefaultTrackingFileManager write directly to tracking files
    * [MRESOLVER-333] Distinguish better resolver errors for artifact availability
    * [MRESOLVER-320] Investigate slower resolving speeds as reported by users
    * [MRESOLVER-291] Undo MRESOLVER-284
    * [MRESOLVER-279] Simplify and improve trusted checksum sources
    * [MRESOLVER-281] Update configurations page with new elements
    * [MRESOLVER-282] Drop PartialFile
    * [MRESOLVER-230] Make supported checksum algorithms extensible
    * [MRESOLVER-231] Extend “smart checksum” feature
    * [MRESOLVER-234] Introduce “provided” checksums feature
    * [MRESOLVER-237] Make all checksum mismatches handled same
    * [MRESOLVER-239] Update and sanitize dependencies
    * [MRESOLVER-244] Deprecate FileTransformer API
    * [MRESOLVER-245] Isolate Hazelcast tests
  * Dependency upgrade

    * [MRESOLVER-311] Upgrade Parent to 39
    * [MRESOLVER-293] Update dependencies, align with Maven
    * [MRESOLVER-272] Update parent POM to 37, remove plugin version overrides, update bnd
    * [MRESOLVER-280] Upgrade invoker, install, deploy, require maven 3.8.4+
    * [MRESOLVER-251] Upgrade Redisson to 3.17.5
    * [MRESOLVER-249] Update Hazelcast to 5.1.1 in named-locks-hazelcast module
  * Add an alias for the wagon connector

  * Build against the standalone JavaEE modules unconditionally

  * Remove the javax.annotation:javax.annotation-api dependency on distribution
    versions that do not incorporate the JavaEE modules

  * Add the glassfish-annotation-api jar to the build classpath

  * Upgrade to upstream version 1.7.3

  * Bug
    * [MRESOLVER-96] - Dependency Injection fails after upgrading to Maven 3.6.2
    * [MRESOLVER-153] - resolver-status.properties file is corrupted due to concurrent writes
    * [MRESOLVER-171] - Resolver fails when compiled on Java 9+ an run on Java 8 due to JDK API breakage
    * [MRESOLVER-189] - Using semaphore-redisson followed by rwlock-redisson on many parallel build of the same project triggers redisson error
  * New Feature
    * [MRESOLVER-90] - HTML content in POM: Maven should validate content before storing in local repo
    * [MRESOLVER-145] - Introduce more SyncContext implementations
  * Improvement
    * [MRESOLVER-103] - Replace deprecated HttpClient classes
    * [MRESOLVER-104] - maven-resolver-demo-maven-plugin uses reserved artifactId
    * [MRESOLVER-147] - Upgrade to Java 8
    * [MRESOLVER-148] - Use vanilla Guice 4 instead of forked Guice 3
    * [MRESOLVER-156] - Active dependency management for Google Guice/Guava
    * [MRESOLVER-168] - add DEBUG message when downloading an artifact from repositories
    * [MRESOLVER-193] - Properly type lock key names in Redis
    * [MRESOLVER-197] - Minors improvements (umbrella)
    * [MRESOLVER-204] - Add a SessionData#computeIfAbsent method
    * [MRESOLVER-214] - Remove clirr configuration
  * Task
    * [MRESOLVER-141] - Review index-based access to collections
    * [MRESOLVER-151] - Enforce a checksum policy to be provided explicitly
    * [MRESOLVER-152] - Perform null checks when interface contracts require it
    * [MRESOLVER-154] - Move SyncContextFactory interface to SPI module
    * [MRESOLVER-155] - Make TrackingFileManager member of DefaultUpdateCheckManager
    * [MRESOLVER-158] - Simplify SimpleDigest class
    * [MRESOLVER-159] - Mark singleton components as Sisu Singletons
    * [MRESOLVER-160] - Deprecate ServiceLocator
    * [MRESOLVER-162] - Restore binary compatibility broken by MRESOLVER-154
    * [MRESOLVER-170] - Deprecate org.eclipse.aether.spi.log
    * [MRESOLVER-172] - Make TrackingFileManager shared singleton component
    * [MRESOLVER-173] - Drop deprecated AetherModule
    * [MRESOLVER-174] - Use all bindings in UTs and tests
    * [MRESOLVER-175] - Drop SyncContextFactory delegates in favor of a selector approach
    * [MRESOLVER-177] - Move pre-/post-processing of metadata from ResolveTask to DefaultMetadataResolver
    * [MRESOLVER-183] - Don't require optional dependencies for Redisson
    * [MRESOLVER-184] - Destroy Redisson semaphores if not used anymore
    * [MRESOLVER-186] - Update Maven version in Resolver Demo Snippets
    * [MRESOLVER-188] - Improve documentation on using the named locks with redis/hazelcast (umbrella)
    * [MRESOLVER-190] - [Regression] Revert MRESOLVER-184
    * [MRESOLVER-191] - Document how to analyze lock issues
    * [MRESOLVER-196] - Document named locks configuration options
    * [MRESOLVER-219] - Implement NamedLock with advisory file locking
    * [MRESOLVER-227] - Refactor NamedLockFactorySelector to a managed component
    * [MRESOLVER-232] - Make SimpleNamedLockFactorySelector logic reusable
  * Sub-task
    * [MRESOLVER-198] - Replace assert by simpler but equivalent calls
    * [MRESOLVER-199] - Java 8 improvements
    * [MRESOLVER-200] - Simplify conditions with the same result and avoid extra validations
    * [MRESOLVER-201] - Make variables final whenever possible
    * [MRESOLVER-202] - Use isEmpty() instead length() <= 0
  * Dependency upgrade
    * [MRESOLVER-185] - Upgrade Redisson to 3.15.6
  * Change of API and incompatible with maven-resolver < 1.7

  * Upgrade to upstream version 1.6.3

  * Bug
    * [MRESOLVER-153] - resolver-status.properties file is corrupted due to concurrent writes
    * [MRESOLVER-171] - Resolver fails when compiled on Java 9+ and run on Java 8 due to JDK API breakage
  * Improvement
    * [MRESOLVER-168] - add DEBUG message when downloading an artifact from repositories
  * Task
    * [MRESOLVER-177] - Move pre-/post-processing of metadata from ResolveTask to DefaultMetadataResolver
  * Needed for maven 3.8.4

  * Do not build/run the tests against the legacy guava20 package

  * Upgrade to upstream version 1.6.2

  * Sub-task
    * [MRESOLVER-139] - Make SimpleDigest use SHA-1 or MD5 only
    * [MRESOLVER-140] - Default to SHA-1 and MD5 hashing algorithms
  * Bug
    * [MRESOLVER-25] - Resume support is broken under high concurrency
    * [MRESOLVER-114] - ArtifactNotFoundExceptions when building in parallel
    * [MRESOLVER-129] - Exclusion has no setters
    * [MRESOLVER-137] - Make OSGi bundles reproducible
    * [MRESOLVER-138] - MRESOLVER-56 introduces severe performance regression
  * New Feature
    * [MRESOLVER-109] - AndDependencySelector should override toString
    * [MRESOLVER-115] - Make checksum algorithms configurable
    * [MRESOLVER-123] - Provide a global locking sync context by default
    * [MRESOLVER-131] - Introduce a Redisson-based SyncContextFactory
    * [MRESOLVER-165] - Add support for mirror selector on external:http:*
    * [MRESOLVER-166] - Add support for blocked repositories/mirrors
  * Improvement
    * [MRESOLVER-56] - Support SHA-256 and SHA-512 as checksums
    * [MRESOLVER-116] - Add page with all supported configuration options
    * [MRESOLVER-125] - Use type conversions returning primitives
    * [MRESOLVER-127] - Don't use boolean for property 'aether.updateCheckManager.sessionState'
    * [MRESOLVER-136] - Migrate from maven-bundle-plugin to bnd-maven-plugin
  * Task
    * [MRESOLVER-119] - Turn log messages to SLF4J placeholders
    * [MRESOLVER-130] - Move GlobalSyncContextFactory to a separate module
    * [MRESOLVER-132] - Remove synchronization in TrackingFileManager
  * Dependency upgrade
    * [MRESOLVER-105] - Update Plexus Components
    * [MRESOLVER-106] - Update HttpComponents
    * [MRESOLVER-107] - Update Wagon Provider API to 3.4.0
    * [MRESOLVER-108] - Update mockito-core to 2.28.2
    * [MRESOLVER-117] - Upgrade SLF4J to 1.7.30
    * [MRESOLVER-118] - Upgrade Sisu Components to 0.3.4
  * Needed for maven 3.8.x

  * Set buildshell to bash for "<<<".

  * Upgrade to upstream version 1.4.2

  * Bug:
    * MRESOLVER-38 – SOE/OOME in DefaultDependencyNode.accept
  * Improvements:

    * MRESOLVER-93 – PathRecordingDependencyVisitor to handle 3 cycles
    * MRESOLVER-102 – make build Reproducible
  * Upgrade to upstream version 1.4.1

  * Task
    * [MRESOLVER-92] - Revert MRESOLVER-7
  * Bug
    * [MRESOLVER-86] - ResolveArtifactMojo from resolver example uses plugin repositories to resolve dependencies
  * New Feature
    * [MRESOLVER-10] - New 'TransitiveDependencyManager' supporting transitive dependency management
    * [MRESOLVER-33] - New 'DefaultDependencyManager' managing dependencies on all levels supporting transitive dependency management
  * Improvement

    * [MRESOLVER-7] - Download dependency POMs in parallel
    * [MRESOLVER-84] - Add support for "release" qualifier
    * [MRESOLVER-87] - Refresh examples to use maven-resolver artifacts for demo
    * [MRESOLVER-88] - Code style cleanup to use Java 7 features
  * Initial packaging of maven-resolver 1.3.1

  * Generate and customize the ant build files

maven-resolver was update to upstream version 1.9.27:

  * Bug Fixes

    * Sync TrackingFileManager with 2.x
  * Update to upstream version 1.9.26

  * New features and improvements
    * GH-1773: Treat 410 Gone as 404 Not Found
    * GH-1737: Revert partially parallel upload change
  * Bug Fixes
    * GH-1768; Drastically simplify auth caching
    * [1.9.x] Bug: GH-1703 Locally cached artifacts defy RRF
  * Documentation updates
    * Clarify that HTTP Transport uses Apache HTTP Client
  * Dependency updates

    * Bump org.redisson:redisson from 3.52.0 to 4.2.0
    * Bump commons-codec:commons-codec from 1.20.0 to 1.21.0
    * Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.26 to 1.27
    * Bump org.apache.maven:maven-parent from 46 to 47
    * Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.0 to 0.25.4
    * Bump mavenVersion from 3.9.11 to 3.9.12
  * Update to upstream version 1.9.25

  * New features and improvements
    * Add scope support for trusted checksums
    * Name mappers cleanup and new GAECV mapper
    * Proper metadata locking support
    * Ability to augment metadata nature for version range request
  * Bug Fixes
    * TrackingFileManager changes
    * Maven filters daemon friendly
    * Remove hack from Basic connector
    * Fix locking issues
  * Documentation updates
    * Updated the documentation to reflect the current list of name mappers
  * Maintenance
    * Mild backport: support same properties as Resolver 2.x
    * Maven resolver lockrepro
    * Bugfix: Java 25 broke test
  * Dependency updates

    * Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.23.1 to 0.25.0
    * Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.24 to 1.26
    * Bump commons-codec:commons-codec from 1.18.0 to 1.20.0
    * Bump org.redisson:redisson from 3.50.0 to 3.52.0
    * Bump com.google.guava:guava from 33.4.8-jre to 33.5.0-jre
    * Bump com.google.code.gson:gson from 2.13.1 to 2.13.2
    * Bump jettyVersion from 9.4.57.v20241219 to 9.4.58.v20250814
    * Bump mavenVersion from 3.9.10 to 3.9.11
  * Update to upstream version 1.9.24

  * New features and improvements
    * Metadata type out of coordinates
    * RFC9457 implementation
    * Intern context strings
  * Maintenance
    * Align plexus-util version with Maven
    * Align guice version with Maven
    * Enable Github Issues (1.9.x branch)
  * Build also maven-resolver-supplier package in separate spec file

  * Add dependency on objectweb-asm to build with sisu 0.9.0.M4

  * Update to upstream version 1.9.23

  * Bug
    * MRESOLVER-659: NPE in trusted checksum post processor if
  * Improvement

    * MRESOLVER-680: Disable checksum by default for .sigstore.json as well
    * MRESOLVER-703: HTTP transport should expose config for max redirects
  * Upgrade to upstream version 3.9.16

  * Bug Fixes
    * Trim threadConfiguration to accept input surrounded with spaces
    * Backport: Maven 3.10.x fixed plugin resolution
  * Dependency updates

    * Bump org.codehaus.plexus:plexus-classworlds from 2.9.0 to 2.11.0
    * [3.9.x] Bump to parent POM 48
    * Bump commons-io:commons-io from 2.21.0 to 2.22.0
    * Bump com.google.guava:guava from 33.5.0-jre to 33.6.0-jre
    * Bump actions/cache from 5.0.4 to 5.0.5
  * There is no need to link the jansi-native library into the tree, since our
    jansi java library will load it from the system anyway

  * Upgrade to upstream version 3.9.15

  * Documentation updates
    * Use new Maven logos in documentation
    * document modelVersion only supported value: 4.0.0
  * Dependency updates

    * Bump actions/upload-artifact from 7.0.0 to 7.0.1
    * Bump org.codehaus.plexus:plexus-utils from 3.6.0 to 3.6.1
    * Bump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3
    * Bump actions/cache from 5.0.3 to 5.0.4
    * Bump actions/download-artifact from 8.0.0 to 8.0.1
  * Upgrade to upstream version 3.9.14

  * Bug Fixes
    * plexus-testing dependencies should be used in test scope
  * Dependency updates

    * Bump actions/upload-artifact from 6.0.0 to 7.0.0
    * Bump actions/download-artifact from 7.0.0 to 8.0.0
  * Upgrade to upstream version 3.9.13

  * Bug Fixes
    * Bug: SecDispatcher is managed by legacy Plexus DI
    * [3.9.x] MavenPluginJavaPrerequisiteChecker: Handle 8/1.8 Java version in ranges as well
  * Maintenance
    * Update Maven plugin versions in default-bindings.xml
    * Migrate to JUnit 5 - avoid using TestCase
  * Dependency updates

    * Maven Resolver 1.9.27
    * Bump resolverVersion from 1.9.25 to 1.9.26
    * Bump version.sisu-maven-plugin from 0.9.0.M4 to 1.0.0
    * Bump actions/cache from 5.0.0 to 5.0.3
    * Bump org.apache.maven:maven-parent from 45 to 47
    * Bump actions/checkout from 6.0.1 to 6.0.2
    * Bump actions/setup-java from 5.1.0 to 5.2.0
    * Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.26 to 1.27
    * Bump org.codehaus.mojo:buildnumber-maven-plugin from 3.2.1 to 3.3.0
    * Bump org.codehaus.plexus:plexus-testing from 2.0.2 to 2.1.0
    * Bump org.ow2.asm:asm from 9.9 to 9.9.1
    * Bump actions/upload-artifact from 5.0.0 to 6.0.0
    * Bump actions/download-artifact from 6.0.0 to 7.0.0
  * Specify required maven-resolver version since the maven-resolver-provider
    requires methods added in 1.9.25

  * Upgrade to upstream version 3.9.12

  * New features and improvements
    * Apply resolver changes and improvements
    * Update formatting of prerequisites-requirements error to improve readability
    * Allow a Maven plugin to require a Java version
    * Use MavenRepositorySystem in ProjectBuildingHelper instead of deprecated RepositorySystem
    * Make maven.config use UTF8
    * Simplify prefix resolution
  * Bug Fixes
    * Add default implementation for new method in MavenPluginManager
    * Repository layout should be used in MavenRepositorySystem
    * Fix plugin prefix resolution when metadata is not available from repository
    * Improve source root modification warning message
    * Bug: bad cache isolation between two sessions
    * Set Guice class loading to CHILD - avoid using terminally deprecated methods
    * Avoid parsing MAVEN_OPTS (3.9.x)
  * Documentation updates
    * clarify repository vs deployment repository
    * add maintained branches
  * Maintenance
    * Add IntelliJ icon
    * Build by JDK 25
    * Deprecate org.apache.maven.repository.RepositorySystem in 3.9.x
  * Build
    * Bump actions/download-artifact from 5.0.0 to 6.0.0
    * Bump actions/upload-artifact from 4.6.2 to 5.0.0
  * Dependency updates

    * Bump actions/cache from 4.2.3 to 5.0.0
    * Bump resolverVersion from 1.9.24 to 1.9.25
    * Bump actions/checkout from 5.0.0 to 6.0.1
    * Bump actions/setup-java from 5.0.0 to 5.1.0
    * Bump commons-cli:commons-cli from 1.9.0 to 1.11.0
    * Bump org.codehaus.plexus:plexus-interpolation from 1.28 to 1.29
    * Bump commons-io:commons-io from 2.19.0 to 2.21.0
    * Bump xmlunitVersion from 2.10.3 to 2.11.0
    * Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.24 to 1.26
    * Bump org.ow2.asm:asm from 9.8 to 9.9
    * Bump com.google.guava:guava from 33.4.8-jre to 33.5.0-jre
  * Upgrade to upstream version 3.9.11

  * New features and improvements
    * Augment version range resolution used repositories
  * Bug Fixes
    * Deduplicate filtered dependency graph
    * Move ensure in boundaries of project lock
  * Maintenance
    * [MNGSITE-393] - remove references to Maven 2
    * Update CONTRIBUTING after GitHub issues enabled
    * Enable Github Issues
    * [MNG-8763] - Remove name from site bannerLeft
  * Build

    * Pin GitHub action versions by hash
    * Build the project by JDK 21 as default
    * Use Maven 3.9.10 for build on GitHub
  * Upgrade to upstream version 3.9.10

  * Bug
    * MNG-8096: Inconsistent dependency resolution behaviour for concurrent multi-module build can cause failures
    * MNG-8169: MINGW support requires \--add-opens java.base/java.lang=ALL-UNNAMED
    * MNG-8170: Maven 3.9.8 contains weird native library for Jansi on Windows/arm64
    * MNG-8211: Maven should fail builds that use CI Friendly versions but have no values set
    * MNG-8248: WARNING: A restricted method in java.lang.System has been called
    * MNG-8256: ProjectDependencyGraph bug: in case of filtering, non-direct module links are lost
    * MNG-8315: Failure of mvn.cmd if a .mvn directory is located at drive root
    * MNG-8396: Maven takes forever to resume
    * MNG-8711: "Duplicate artifact" in LifecycleDependencyResolver
  * Improvement
    * MNG-8370: Introduce maven.repo.local.head
    * MNG-8399: JDK 24+ issues warning about usage of sun.misc.Unsafe
    * MNG-8707: Add methods to remove compile and test source roots
    * MNG-8712: improve dependency version explanation: it's a requirement, not always effective version
    * MNG-8717: Remove maven-plugin-plugin:addPluginArtifactMetadata from default binding
    * MNG-8722: Use a single standalone version of asm
    * MNG-8731: Use https for xsi:schemaLocation in generated descriptors
    * MNG-8734: Simplify scripting like "get project version" cases
  * Task

    * MNG-8728: Bump Eclipse Sisu from 0.9.0.M3 to 0.9.0.M4 and use Java 24 on CI
  * Link also the objectweb-asm/asm to the lib directory

    * MNG-8177: Warning

xmvn-connector was updated to fix:

  * Add dependency on objectweb-asm to build with sisu 0.9.0.M4

  * Upgrade to version 4.3.0

  * Changes:
    * Fix typo in JavadocMojo
    * Reproducible javadoc
    * Reproducible manifest injection
    * Deprecate UUIDs
    * Implement MetadataResult.getPackageMetadataMap()

xmvn-mojo was updated to fix:

Upgrade to version 4.3.0

  * Changes:
    * Fix typo in JavadocMojo
    * Reproducible javadoc
    * Reproducible manifest injection
    * Deprecate UUIDs
    * Implement MetadataResult.getPackageMetadataMap()

xmvn-parent was updated to fix:

  * Upgrade to version 4.3.0
  * Changes:
    * Fix typo in JavadocMojo
    * Reproducible javadoc
    * Reproducible manifest injection
    * Deprecate UUIDs
    * Implement MetadataResult.getPackageMetadataMap()

xmvn-tools was updated to:

  * The new commons-compress needs commons-lang3

  * Upgrade to version 4.3.0

  * Changes:
    * Fix typo in JavadocMojo
    * Reproducible javadoc
    * Reproducible manifest injection
    * Deprecate UUIDs
    * Implement MetadataResult.getPackageMetadataMap()

xmvn was updated to fix:

  * Adapt to no libjansi.so linked into the arch independent path

  * Fix build after removal of the default %%{java_home} define

  * Upgrade to version 4.3.0

  * Changes:
    * Fix typo in JavadocMojo
    * Reproducible javadoc
    * Reproducible manifest injection
    * Deprecate UUIDs
    * Implement MetadataResult.getPackageMetadataMap()

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server 15 SP4 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3390=1

  * SUSE Linux Enterprise Server for SAP Applications 15 SP4  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3390=1

  * Basesystem Module 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3390=1

  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3390=1

  * SUSE Linux Enterprise Server 15 SP6 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3390=1

  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3390=1

  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3390=1

  * Development Tools Module 15-SP7  
    zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3390=1

  * SUSE Linux Enterprise Server for SAP Applications 15 SP6  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3390=1

  * SUSE Linux Enterprise Server 15 SP5 LTSS  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3390=1

  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3390=1

  * SUSE Linux Enterprise Server for SAP Applications 15 SP5  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3390=1

## Package List:

  * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
    * xmvn-minimal-4.3.0-150200.3.30.1
    * jansi-2.4.0-150200.3.9.1
    * xmvn-4.3.0-150200.3.30.1
    * maven-lib-3.9.16-150200.4.33.1
    * maven-3.9.16-150200.4.33.1
  * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch)
    * xmvn-install-4.3.0-150200.3.30.1
    * beust-jcommander-1.83-150200.3.15.1
    * apache-commons-lang3-3.20.0-150200.3.15.2
    * maven-resolver-api-1.9.27-150200.3.29.1
    * maven-resolver-named-locks-1.9.27-150200.3.29.1
    * xmvn-resolve-4.3.0-150200.3.30.1
    * apache-commons-compress-1.28.0-150200.3.21.1
    * xmvn-core-4.3.0-150200.3.30.1
    * maven-resolver-connector-basic-1.9.27-150200.3.29.1
    * maven-resolver-transport-file-1.9.27-150200.3.29.1
    * plexus-interpolation-1.27.0-150200.3.9.1
    * maven-resolver-transport-http-1.9.27-150200.3.29.1
    * maven-resolver-transport-wagon-1.9.27-150200.3.29.1
    * xmvn-connector-4.3.0-150200.3.30.1
    * xmvn-mojo-4.3.0-150200.3.30.1
    * maven-resolver-impl-1.9.27-150200.3.29.1
    * maven-resolver-spi-1.9.27-150200.3.29.1
    * xmvn-api-4.3.0-150200.3.30.1
    * maven-resolver-util-1.9.27-150200.3.29.1
    * google-guice-6.0.0-150200.3.13.2
    * plexus-xml-3.0.1-150200.5.10.1
    * guava-33.2.1-150200.3.15.1
    * xmvn-subst-4.3.0-150200.3.30.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
    * xmvn-install-4.3.0-150200.3.30.1
    * beust-jcommander-1.83-150200.3.15.1
    * apache-commons-lang3-3.20.0-150200.3.15.2
    * maven-resolver-api-1.9.27-150200.3.29.1
    * maven-resolver-named-locks-1.9.27-150200.3.29.1
    * xmvn-resolve-4.3.0-150200.3.30.1
    * apache-commons-compress-1.28.0-150200.3.21.1
    * xmvn-core-4.3.0-150200.3.30.1
    * maven-resolver-connector-basic-1.9.27-150200.3.29.1
    * maven-resolver-transport-file-1.9.27-150200.3.29.1
    * plexus-interpolation-1.27.0-150200.3.9.1
    * maven-resolver-transport-http-1.9.27-150200.3.29.1
    * maven-resolver-transport-wagon-1.9.27-150200.3.29.1
    * xmvn-connector-4.3.0-150200.3.30.1
    * xmvn-mojo-4.3.0-150200.3.30.1
    * maven-resolver-impl-1.9.27-150200.3.29.1
    * maven-resolver-spi-1.9.27-150200.3.29.1
    * xmvn-api-4.3.0-150200.3.30.1
    * maven-resolver-util-1.9.27-150200.3.29.1
    * google-guice-6.0.0-150200.3.13.2
    * plexus-xml-3.0.1-150200.5.10.1
    * guava-33.2.1-150200.3.15.1
    * xmvn-subst-4.3.0-150200.3.30.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
    * jansi-debuginfo-2.4.0-150200.3.9.1
    * xmvn-minimal-4.3.0-150200.3.30.1
    * jansi-2.4.0-150200.3.9.1
    * xmvn-4.3.0-150200.3.30.1
    * maven-lib-3.9.16-150200.4.33.1
    * maven-3.9.16-150200.4.33.1
  * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
    * jansi-debuginfo-2.4.0-150200.3.9.1
    * xmvn-minimal-4.3.0-150200.3.30.1
    * jansi-2.4.0-150200.3.9.1
    * xmvn-4.3.0-150200.3.30.1
    * maven-lib-3.9.16-150200.4.33.1
    * maven-3.9.16-150200.4.33.1
  * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
    * xmvn-install-4.3.0-150200.3.30.1
    * beust-jcommander-1.83-150200.3.15.1
    * apache-commons-lang3-3.20.0-150200.3.15.2
    * maven-resolver-api-1.9.27-150200.3.29.1
    * maven-resolver-named-locks-1.9.27-150200.3.29.1
    * xmvn-resolve-4.3.0-150200.3.30.1
    * apache-commons-compress-1.28.0-150200.3.21.1
    * xmvn-core-4.3.0-150200.3.30.1
    * maven-resolver-connector-basic-1.9.27-150200.3.29.1
    * maven-resolver-transport-file-1.9.27-150200.3.29.1
    * plexus-interpolation-1.27.0-150200.3.9.1
    * maven-resolver-transport-wagon-1.9.27-150200.3.29.1
    * maven-resolver-transport-http-1.9.27-150200.3.29.1
    * xmvn-connector-4.3.0-150200.3.30.1
    * xmvn-mojo-4.3.0-150200.3.30.1
    * maven-resolver-impl-1.9.27-150200.3.29.1
    * maven-resolver-spi-1.9.27-150200.3.29.1
    * xmvn-api-4.3.0-150200.3.30.1
    * maven-resolver-util-1.9.27-150200.3.29.1
    * google-guice-6.0.0-150200.3.13.2
    * plexus-xml-3.0.1-150200.5.10.1
    * guava-33.2.1-150200.3.15.1
    * xmvn-subst-4.3.0-150200.3.30.1
  * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
    * jansi-debuginfo-2.4.0-150200.3.9.1
    * xmvn-minimal-4.3.0-150200.3.30.1
    * jansi-2.4.0-150200.3.9.1
    * xmvn-4.3.0-150200.3.30.1
    * maven-lib-3.9.16-150200.4.33.1
    * maven-3.9.16-150200.4.33.1
  * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch)
    * xmvn-install-4.3.0-150200.3.30.1
    * beust-jcommander-1.83-150200.3.15.1
    * apache-commons-lang3-3.20.0-150200.3.15.2
    * maven-resolver-api-1.9.27-150200.3.29.1
    * maven-resolver-named-locks-1.9.27-150200.3.29.1
    * xmvn-resolve-4.3.0-150200.3.30.1
    * apache-commons-compress-1.28.0-150200.3.21.1
    * xmvn-core-4.3.0-150200.3.30.1
    * maven-resolver-connector-basic-1.9.27-150200.3.29.1
    * maven-resolver-transport-file-1.9.27-150200.3.29.1
    * plexus-interpolation-1.27.0-150200.3.9.1
    * maven-resolver-transport-http-1.9.27-150200.3.29.1
    * maven-resolver-transport-wagon-1.9.27-150200.3.29.1
    * xmvn-connector-4.3.0-150200.3.30.1
    * xmvn-mojo-4.3.0-150200.3.30.1
    * maven-resolver-impl-1.9.27-150200.3.29.1
    * maven-resolver-spi-1.9.27-150200.3.29.1
    * xmvn-api-4.3.0-150200.3.30.1
    * maven-resolver-util-1.9.27-150200.3.29.1
    * google-guice-6.0.0-150200.3.13.2
    * plexus-xml-3.0.1-150200.5.10.1
    * guava-33.2.1-150200.3.15.1
    * xmvn-subst-4.3.0-150200.3.30.1
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch)
    * xmvn-install-4.3.0-150200.3.30.1
    * beust-jcommander-1.83-150200.3.15.1
    * apache-commons-lang3-3.20.0-150200.3.15.2
    * maven-resolver-api-1.9.27-150200.3.29.1
    * maven-resolver-named-locks-1.9.27-150200.3.29.1
    * xmvn-resolve-4.3.0-150200.3.30.1
    * apache-commons-compress-1.28.0-150200.3.21.1
    * xmvn-core-4.3.0-150200.3.30.1
    * maven-resolver-connector-basic-1.9.27-150200.3.29.1
    * maven-resolver-transport-file-1.9.27-150200.3.29.1
    * plexus-interpolation-1.27.0-150200.3.9.1
    * maven-resolver-transport-wagon-1.9.27-150200.3.29.1
    * maven-resolver-transport-http-1.9.27-150200.3.29.1
    * xmvn-connector-4.3.0-150200.3.30.1
    * maven-resolver-impl-1.9.27-150200.3.29.1
    * xmvn-mojo-4.3.0-150200.3.30.1
    * maven-resolver-spi-1.9.27-150200.3.29.1
    * xmvn-api-4.3.0-150200.3.30.1
    * maven-resolver-util-1.9.27-150200.3.29.1
    * google-guice-6.0.0-150200.3.13.2
    * plexus-xml-3.0.1-150200.5.10.1
    * guava-33.2.1-150200.3.15.1
    * xmvn-subst-4.3.0-150200.3.30.1
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64
    x86_64)
    * xmvn-minimal-4.3.0-150200.3.30.1
    * jansi-2.4.0-150200.3.9.1
    * xmvn-4.3.0-150200.3.30.1
    * maven-lib-3.9.16-150200.4.33.1
    * maven-3.9.16-150200.4.33.1
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
    x86_64)
    * jansi-debuginfo-2.4.0-150200.3.9.1
    * xmvn-minimal-4.3.0-150200.3.30.1
    * jansi-2.4.0-150200.3.9.1
    * xmvn-4.3.0-150200.3.30.1
    * maven-lib-3.9.16-150200.4.33.1
    * maven-3.9.16-150200.4.33.1
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch)
    * xmvn-install-4.3.0-150200.3.30.1
    * beust-jcommander-1.83-150200.3.15.1
    * apache-commons-lang3-3.20.0-150200.3.15.2
    * maven-resolver-api-1.9.27-150200.3.29.1
    * maven-resolver-named-locks-1.9.27-150200.3.29.1
    * xmvn-resolve-4.3.0-150200.3.30.1
    * apache-commons-compress-1.28.0-150200.3.21.1
    * xmvn-core-4.3.0-150200.3.30.1
    * maven-resolver-connector-basic-1.9.27-150200.3.29.1
    * maven-resolver-transport-file-1.9.27-150200.3.29.1
    * plexus-interpolation-1.27.0-150200.3.9.1
    * maven-resolver-transport-http-1.9.27-150200.3.29.1
    * maven-resolver-transport-wagon-1.9.27-150200.3.29.1
    * xmvn-connector-4.3.0-150200.3.30.1
    * xmvn-mojo-4.3.0-150200.3.30.1
    * maven-resolver-impl-1.9.27-150200.3.29.1
    * maven-resolver-spi-1.9.27-150200.3.29.1
    * xmvn-api-4.3.0-150200.3.30.1
    * maven-resolver-util-1.9.27-150200.3.29.1
    * google-guice-6.0.0-150200.3.13.2
    * plexus-xml-3.0.1-150200.5.10.1
    * guava-33.2.1-150200.3.15.1
    * xmvn-subst-4.3.0-150200.3.30.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch)
    * xmvn-install-4.3.0-150200.3.30.1
    * beust-jcommander-1.83-150200.3.15.1
    * apache-commons-lang3-3.20.0-150200.3.15.2
    * maven-resolver-api-1.9.27-150200.3.29.1
    * maven-resolver-named-locks-1.9.27-150200.3.29.1
    * xmvn-resolve-4.3.0-150200.3.30.1
    * apache-commons-compress-1.28.0-150200.3.21.1
    * xmvn-core-4.3.0-150200.3.30.1
    * maven-resolver-connector-basic-1.9.27-150200.3.29.1
    * maven-resolver-transport-file-1.9.27-150200.3.29.1
    * plexus-interpolation-1.27.0-150200.3.9.1
    * maven-resolver-transport-wagon-1.9.27-150200.3.29.1
    * maven-resolver-transport-http-1.9.27-150200.3.29.1
    * xmvn-connector-4.3.0-150200.3.30.1
    * xmvn-mojo-4.3.0-150200.3.30.1
    * maven-resolver-impl-1.9.27-150200.3.29.1
    * maven-resolver-spi-1.9.27-150200.3.29.1
    * xmvn-api-4.3.0-150200.3.30.1
    * maven-resolver-util-1.9.27-150200.3.29.1
    * google-guice-6.0.0-150200.3.13.2
    * plexus-xml-3.0.1-150200.5.10.1
    * guava-33.2.1-150200.3.15.1
    * xmvn-subst-4.3.0-150200.3.30.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
    * jansi-debuginfo-2.4.0-150200.3.9.1
    * xmvn-minimal-4.3.0-150200.3.30.1
    * jansi-2.4.0-150200.3.9.1
    * xmvn-4.3.0-150200.3.30.1
    * maven-lib-3.9.16-150200.4.33.1
    * maven-3.9.16-150200.4.33.1
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch)
    * xmvn-install-4.3.0-150200.3.30.1
    * beust-jcommander-1.83-150200.3.15.1
    * apache-commons-lang3-3.20.0-150200.3.15.2
    * maven-resolver-api-1.9.27-150200.3.29.1
    * maven-resolver-named-locks-1.9.27-150200.3.29.1
    * xmvn-resolve-4.3.0-150200.3.30.1
    * apache-commons-compress-1.28.0-150200.3.21.1
    * xmvn-core-4.3.0-150200.3.30.1
    * maven-resolver-connector-basic-1.9.27-150200.3.29.1
    * maven-resolver-transport-file-1.9.27-150200.3.29.1
    * plexus-interpolation-1.27.0-150200.3.9.1
    * maven-resolver-transport-wagon-1.9.27-150200.3.29.1
    * maven-resolver-transport-http-1.9.27-150200.3.29.1
    * xmvn-connector-4.3.0-150200.3.30.1
    * xmvn-mojo-4.3.0-150200.3.30.1
    * maven-resolver-impl-1.9.27-150200.3.29.1
    * maven-resolver-spi-1.9.27-150200.3.29.1
    * xmvn-api-4.3.0-150200.3.30.1
    * maven-resolver-util-1.9.27-150200.3.29.1
    * google-guice-6.0.0-150200.3.13.2
    * plexus-xml-3.0.1-150200.5.10.1
    * guava-33.2.1-150200.3.15.1
    * xmvn-subst-4.3.0-150200.3.30.1
  * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
    x86_64)
    * jansi-debuginfo-2.4.0-150200.3.9.1
    * xmvn-minimal-4.3.0-150200.3.30.1
    * jansi-2.4.0-150200.3.9.1
    * xmvn-4.3.0-150200.3.30.1
    * maven-lib-3.9.16-150200.4.33.1
    * maven-3.9.16-150200.4.33.1
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch)
    * xmvn-install-4.3.0-150200.3.30.1
    * beust-jcommander-1.83-150200.3.15.1
    * apache-commons-lang3-3.20.0-150200.3.15.2
    * maven-resolver-api-1.9.27-150200.3.29.1
    * maven-resolver-named-locks-1.9.27-150200.3.29.1
    * xmvn-resolve-4.3.0-150200.3.30.1
    * apache-commons-compress-1.28.0-150200.3.21.1
    * xmvn-core-4.3.0-150200.3.30.1
    * maven-resolver-connector-basic-1.9.27-150200.3.29.1
    * maven-resolver-transport-file-1.9.27-150200.3.29.1
    * plexus-interpolation-1.27.0-150200.3.9.1
    * maven-resolver-transport-wagon-1.9.27-150200.3.29.1
    * maven-resolver-transport-http-1.9.27-150200.3.29.1
    * xmvn-connector-4.3.0-150200.3.30.1
    * xmvn-mojo-4.3.0-150200.3.30.1
    * maven-resolver-impl-1.9.27-150200.3.29.1
    * maven-resolver-spi-1.9.27-150200.3.29.1
    * xmvn-api-4.3.0-150200.3.30.1
    * maven-resolver-util-1.9.27-150200.3.29.1
    * google-guice-6.0.0-150200.3.13.2
    * plexus-xml-3.0.1-150200.5.10.1
    * guava-33.2.1-150200.3.15.1
    * xmvn-subst-4.3.0-150200.3.30.1
  * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64
    x86_64)
    * xmvn-minimal-4.3.0-150200.3.30.1
    * jansi-2.4.0-150200.3.9.1
    * xmvn-4.3.0-150200.3.30.1
    * maven-lib-3.9.16-150200.4.33.1
    * maven-3.9.16-150200.4.33.1
  * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64)
    * jansi-debuginfo-2.4.0-150200.3.9.1
    * xmvn-minimal-4.3.0-150200.3.30.1
    * jansi-2.4.0-150200.3.9.1
    * xmvn-4.3.0-150200.3.30.1
    * maven-lib-3.9.16-150200.4.33.1
    * maven-3.9.16-150200.4.33.1
  * Development Tools Module 15-SP7 (noarch)
    * xmvn-install-4.3.0-150200.3.30.1
    * beust-jcommander-1.83-150200.3.15.1
    * maven-resolver-api-1.9.27-150200.3.29.1
    * maven-resolver-named-locks-1.9.27-150200.3.29.1
    * xmvn-resolve-4.3.0-150200.3.30.1
    * xmvn-core-4.3.0-150200.3.30.1
    * maven-resolver-connector-basic-1.9.27-150200.3.29.1
    * maven-resolver-transport-file-1.9.27-150200.3.29.1
    * plexus-interpolation-1.27.0-150200.3.9.1
    * maven-resolver-transport-wagon-1.9.27-150200.3.29.1
    * maven-resolver-transport-http-1.9.27-150200.3.29.1
    * xmvn-connector-4.3.0-150200.3.30.1
    * xmvn-mojo-4.3.0-150200.3.30.1
    * maven-resolver-impl-1.9.27-150200.3.29.1
    * maven-resolver-spi-1.9.27-150200.3.29.1
    * xmvn-api-4.3.0-150200.3.30.1
    * maven-resolver-util-1.9.27-150200.3.29.1
    * google-guice-6.0.0-150200.3.13.2
    * plexus-xml-3.0.1-150200.5.10.1
    * guava-33.2.1-150200.3.15.1
    * xmvn-subst-4.3.0-150200.3.30.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch)
    * xmvn-install-4.3.0-150200.3.30.1
    * beust-jcommander-1.83-150200.3.15.1
    * apache-commons-lang3-3.20.0-150200.3.15.2
    * maven-resolver-api-1.9.27-150200.3.29.1
    * maven-resolver-named-locks-1.9.27-150200.3.29.1
    * xmvn-resolve-4.3.0-150200.3.30.1
    * apache-commons-compress-1.28.0-150200.3.21.1
    * xmvn-core-4.3.0-150200.3.30.1
    * maven-resolver-connector-basic-1.9.27-150200.3.29.1
    * maven-resolver-transport-file-1.9.27-150200.3.29.1
    * plexus-interpolation-1.27.0-150200.3.9.1
    * maven-resolver-transport-http-1.9.27-150200.3.29.1
    * maven-resolver-transport-wagon-1.9.27-150200.3.29.1
    * xmvn-connector-4.3.0-150200.3.30.1
    * xmvn-mojo-4.3.0-150200.3.30.1
    * maven-resolver-impl-1.9.27-150200.3.29.1
    * maven-resolver-spi-1.9.27-150200.3.29.1
    * xmvn-api-4.3.0-150200.3.30.1
    * maven-resolver-util-1.9.27-150200.3.29.1
    * google-guice-6.0.0-150200.3.13.2
    * plexus-xml-3.0.1-150200.5.10.1
    * guava-33.2.1-150200.3.15.1
    * xmvn-subst-4.3.0-150200.3.30.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
    * xmvn-minimal-4.3.0-150200.3.30.1
    * jansi-2.4.0-150200.3.9.1
    * xmvn-4.3.0-150200.3.30.1
    * maven-lib-3.9.16-150200.4.33.1
    * maven-3.9.16-150200.4.33.1
  * Basesystem Module 15-SP7 (noarch)
    * apache-commons-lang3-3.20.0-150200.3.15.2
    * apache-commons-compress-1.28.0-150200.3.21.1

## References:

  * https://www.suse.com/security/cve/CVE-2025-48924.html

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20260728/5153b178/attachment.htm>


More information about the sle-security-updates mailing list