SSerguey Asael Shinder
Java coding notes: the JVM, and writing software that lasts

Serguey Asael Shinder: The free security fix is on the latest line

· by Serguey Asael Shinder / Serguey Shinder

On 7 October Gradle published three high-severity advisories — two ways to make the daemon deserialize hostile objects, and a resolver that moved to the next repository after a TLS error. The interesting part for most teams is not the bugs. It is the table at the bottom of each advisory.

The table. The fix is available as open source in 9.8.1 and 8.14.6. For 9.7.2, 9.6.2, 9.5.2, 9.4.2, 9.3.2, 9.2.2, 9.1.x and 7.6.7, the availability column reads Gradle Security Subscription.

So the free paths are: the newest 9.x minor, or 8.14.6 on the 8.x line. Everything in between has a fix that exists and is not free.

What that does to "we pinned it". Pinning a build tool to a known-good version is a reasonable habit: it keeps builds reproducible and avoids surprise breakage. Its hidden assumption is that a security fix, when it comes, will be backported to wherever you are — or that upgrading is cheap enough to do when needed. For this round, the first part holds only for those who pay. The second was never guaranteed: 9.8.1 itself fixes a regression in 9.8.0 that broke Quarkus test log capture.

Serguey Asael Shinder: The free security fix is on the latest line
The free security fix is on the latest line — Serguey Asael Shinder

Three readings.

What to do with it. Treat the wrapper version as a dependency with a support window, not a constant. Keep a standing path to the newest minor — a CI job that runs the build on it weekly costs less than discovering, on the day an advisory lands, that the upgrade is three minors and two regressions away. And when a tool's security fixes stop being free on older lines, write that into the decision record where the pin was chosen, because whoever revisits the pin should know what it now costs.

The availability table is quoted from the advisories as published on 7 October; Gradle's subscription terms are not described here.