Skip to content

fix(deps): update dependency io.micrometer:micrometer-core to v1.15.12 [security] - #995

Merged
dkropachev merged 1 commit into
scylla-4.xfrom
renovate/maven-io.micrometer-micrometer-core-vulnerability
Aug 11, 2026
Merged

dkropachev merged 1 commit into
scylla-4.xfrom
renovate/maven-io.micrometer-micrometer-core-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Aug 8, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Change Age Confidence
io.micrometer:micrometer-core 1.15.4 → 1.15.12 age confidence

Micrometer gRPC server instrumentation DoS

CVE-2026-40983 / GHSA-w737-wx49-qj23

More information

Details

In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition.

Affected versions:
Micrometer 1.16.0 through 1.16.5; 1.15.0 through 1.15.11.

Severity

  • CVSS Score: 7.5 / 10 (High)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

micrometer-metrics/micrometer (io.micrometer:micrometer-core)

v1.15.12: 1.15.12

Compare Source

🐞 Bug Fixes
  • ArrayIndexOutOfBoundsException when using LongTaskTimer #​3877
  • Jetty 12's TimedHandler marks some requests with outcome UNKNOWN #​7276
  • MeterRegistry closes HighCardinalityTagsDetector twice if the registry is closed twice #​7409
  • Reduce allocation in HTTP server instrumentation #​7580
  • Reduce allocation in gRPC server convention #​7581
📔 Documentation
  • Clarify time series produced by LongTaskTimer when using Prometheus #​6507
  • Document metrics that need to close the MeterBinder #​4624
  • Multigauge Documentation lacks overwrite=true #​4403
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​izeye, @​jewoodev, @​codingkiddo, @​schiemon, @​blaspat

v1.15.11: 1.15.11

Compare Source

🐞 Bug Fixes
  • Invalid reflection hint in micrometer-core for native GraalVM 25 build #​7316
🔨 Dependency Upgrades
  • Bump org.apache.maven:maven-resolver-provider from 3.9.13 to 3.9.14 #​7280
  • Bump spring6 from 6.2.16 to 6.2.17 #​7294
❤️ Contributors

@​Joowon-Seo and @​ribafish
Thank you to all the contributors who worked on this release:

v1.15.10: 1.15.10

Compare Source

📔 Documentation
  • Document (Default)MeterObservationHandler #​6361
  • Document statsd UDS config #​5730
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​seonghyeoklee, @​kangdaeun1022, and @​izeye

v1.15.9: 1.15.9

Compare Source

🐞 Bug Fixes
  • Add immutable noop Observation.Context #​7133
  • OSGi test isn't reporting failures #​7060
📔 Documentation
  • Docs: Align AsciiDoc callout syntax #​7148
  • Improve documentation of ExecutorServiceMetrics #​7083
🔨 Dependency Upgrades
  • Bump dropwizard-metrics from 4.2.37 to 4.2.38 #​7120
  • Bump gradle-wrapper from 8.14.3 to 8.14.4 #​7112
  • Bump io.spring.develocity.conventions from 0.0.24 to 0.0.25 #​7099
  • Bump org.assertj:assertj-core from 3.27.6 to 3.27.7 #​7123
❤️ Contributors

@​izeye, @​mateusz-nalepa, and @​tkmsaaaam
Thank you to all the contributors who worked on this release:

v1.15.8: 1.15.8

Compare Source

🐞 Bug Fixes
  • ExecutorServiceMetrics: repeatedly logs exception when monitoring ThreadPerTaskExecutor without --add-opens #​6726
🔨 Dependency Upgrades
  • Bump maven-resolver from 1.9.24 to 1.9.25 #​6965
  • Bump spring6 from 6.2.14 to 6.2.15 #​6969
  • Bump testcontainers from 1.21.3 to 1.21.4 #​6993
❤️ Contributors

Thank you to all the contributors who worked on this release:
@​izeye

v1.15.7: 1.15.7

Compare Source

🐞 Bug Fixes
  • Don't filter log events in LogbackMetricsBenchmark #​6891
📔 Documentation
  • Add link to the latest Micrometer Team talk #​6881
  • Make cross-references more consistent in the docs #​6915
🔨 Dependency Upgrades
  • Bump spring6 from 6.2.12 to 6.2.14 #​6911
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​MiLabuda, and @​ngocnhan-tran1996

v1.15.6: 1.15.6

Compare Source

🐞 Bug Fixes
  • Exclude java.* from OSGI Import-Package #​6810
📔 Documentation
  • Add a note about client-side percentiles with histogram #​6836
  • Add docs for HighCardinalityTagsDetector #​6822

v1.15.5: 1.15.5

🐞 Bug Fixes
  • Close scope in same thread in ObservedAspect #​6727
  • Synchronize access of current connections in JettyConnectionMetrics #​6578
🔨 Dependency Upgrades
  • Bump dropwizard-metrics from 4.2.36 to 4.2.37 #​6733
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​deadok22 and @​pema4


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Never, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@coderabbitai

coderabbitai Bot commented Aug 8, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: QUIET

Plan: Pro Plus

Run ID: 2535a1f1-ec3c-4164-b893-2d85486d74ff

📥 Commits

Reviewing files that changed from the base of the PR and between 1bb0a6d and 950d92e.

📒 Files selected for processing (1)
  • pom.xml

📝 Walkthrough

Walkthrough

The pull request updates the managed io.micrometer:micrometer-core dependency in pom.xml from version 1.15.4 to 1.15.12.

Possibly related PRs

Suggested labels: dependencies, java

Suggested reviewers: scylladb-promoter, dkropachev, nikagra

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the Micrometer dependency update and its security purpose.
Description check ✅ Passed The description explains the dependency update, security vulnerability, affected versions, and included release changes.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Aug 8, 2026
@dkropachev
dkropachev merged commit 9cc36ed into scylla-4.x Aug 11, 2026
35 checks passed
@dkropachev
dkropachev deleted the renovate/maven-io.micrometer-micrometer-core-vulnerability branch August 11, 2026 13:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant