Security uplift 93/140693/1
authoradheli.tavares <adheli.tavares@est.tech>
Mon, 14 Apr 2025 15:28:15 +0000 (16:28 +0100)
committeradheli.tavares <adheli.tavares@est.tech>
Mon, 14 Apr 2025 15:29:27 +0000 (16:29 +0100)
Issue-ID: POLICY-5302
Change-Id: I4c59cf0107ed8366636a0944488d0f81030d91b3
Signed-off-by: adheli.tavares <adheli.tavares@est.tech>
integration/pom.xml

index 76a6720..200664e 100644 (file)
@@ -2,7 +2,7 @@
   ============LICENSE_START=======================================================
    Copyright (C) 2018 Ericsson. All rights reserved.
    Modifications Copyright (C) 2018-2023 AT&T. All rights reserved.
-   Modifications Copyright (C) 2019-2025 Nordix Foundation.
+   Modifications Copyright (C) 2019-2025 OpenInfra Foundation Europe. All rights reserved.
    Modifications Copyright (C) 2020-2022 Bell Canada.
   ================================================================================
   Licensed under the Apache License, Version 2.0 (the "License");
         <docker.pull.registry>nexus3.onap.org:10001</docker.pull.registry>
         <docker.push.registry>nexus3.onap.org:10003</docker.push.registry>
         <!-- Dependency Versions -->
-        <version.beanutils>1.9.4</version.beanutils>
+        <version.beanutils>1.10.1</version.beanutils>
         <version.bytebuddy>1.14.13</version.bytebuddy>
         <version.ccsdk>1.7.1</version.ccsdk>
         <version.cucumber>7.15.0</version.cucumber>
         <version.docker-java>3.3.2</version.docker-java>
         <version.drools>8.40.1.Final</version.drools>
         <version.frontend.maven>1.13.4</version.frontend.maven>
-        <version.guava>33.0.0-jre</version.guava>
+        <version.guava>33.4.6-jre</version.guava>
         <version.hamcrest>3.0</version.hamcrest>
-        <version.httpclient>5.4.1</version.httpclient>
-        <version.httpcore>5.3.2</version.httpcore>
-        <version.io.prometheus>1.3.5</version.io.prometheus>
-        <version.jackson>2.17.2</version.jackson>
+        <version.httpclient>5.4.3</version.httpclient>
+        <version.httpcore>5.3.4</version.httpcore>
+        <version.io.prometheus>1.3.6</version.io.prometheus>
+        <version.jackson>2.18.3</version.jackson>
         <version.jacoco>0.8.11</version.jacoco>
         <version.jaxb>4.0.5</version.jaxb>
         <version.jersey>3.1.10</version.jersey>
-        <version.jetty>12.0.16</version.jetty>
+        <version.jetty>12.0.19</version.jetty>
         <version.jexl3>3.2.1</version.jexl3>
         <version.json-path>2.9.0</version.json-path>
         <version.json-schema-friend>0.12.4</version.json-schema-friend>
-        <version.json-schema-validator>1.5.0</version.json-schema-validator>
+        <version.json-schema-validator>1.5.6</version.json-schema-validator>
         <version.jupiter>5.11.3</version.jupiter>
         <version.kafka>3.9.0</version.kafka>
-        <version.kotlin>2.1.10</version.kotlin>
-        <version.log4j>2.23.1</version.log4j>
+        <version.kotlin>2.1.20</version.kotlin>
+        <version.log4j>2.24.3</version.log4j>
         <version.logback>1.5.18</version.logback>
         <version.maven-checkstyle-plugin>3.3.1</version.maven-checkstyle-plugin>
         <version.maven-remote-resources-plugin>3.1.0</version.maven-remote-resources-plugin>
-        <version.micrometer>1.14.3</version.micrometer>
+        <version.micrometer>1.14.5</version.micrometer>
         <version.mockito>5.5.0</version.mockito>
         <version.mockserver>5.15.0</version.mockserver>
         <version.nsa-cambria>1.2.1-oss</version.nsa-cambria>
         <version.nsa-sa-client>1.3.0-oss</version.nsa-sa-client>
         <version.opentel>1.43.0</version.opentel>
-        <version.plexus>3.5.0</version.plexus>
+        <version.plexus>3.6.0</version.plexus>
         <version.sdc-dist>2.1.1</version.sdc-dist>
         <version.sdc-tosca>1.9.0</version.sdc-tosca>
-        <version.slf4j>2.0.13</version.slf4j>
-        <version.spring>6.2.3</version.spring>
-        <version.springboot>3.4.3</version.springboot>
-        <version.spring-data>3.4.3</version.spring-data>
-        <version.spring-security>6.4.3</version.spring-security>
+        <version.slf4j>2.0.17</version.slf4j>
+        <version.spring>6.2.5</version.spring>
+        <version.springboot>3.4.4</version.springboot>
+        <version.spring-data>3.4.4</version.spring-data>
+        <version.spring-security>6.4.4</version.spring-security>
         <version.sonar>3.11.0.3922</version.sonar>
-        <version.swagger.codegen.v3>3.0.52</version.swagger.codegen.v3>
-        <version.swagger.core.v3>2.2.28</version.swagger.core.v3>
+        <version.swagger.codegen.v3>3.0.68</version.swagger.codegen.v3>
+        <version.swagger.core.v3>2.2.29</version.swagger.core.v3>
         <surefireArgLine>
             --add-opens java.base/java.time=ALL-UNNAMED
             --add-opens java.base/java.util=ALL-UNNAMED
+            --add-opens java.base/java.lang=ALL-UNNAMED
             --add-opens java.sql/java.sql=ALL-UNNAMED
         </surefireArgLine>
     </properties>
             <dependency>
                 <groupId>com.google.code.gson</groupId>
                 <artifactId>gson</artifactId>
-                <version>2.10.1</version>
+                <version>2.12.1</version>
             </dependency>
             <dependency>
                 <groupId>com.google.guava</groupId>
             <dependency>
                 <groupId>com.google.re2j</groupId>
                 <artifactId>re2j</artifactId>
-                <version>1.7</version>
+                <version>1.8</version>
             </dependency>
             <dependency>
                 <groupId>com.jayway.jsonpath</groupId>
             <dependency>
                 <groupId>commons-cli</groupId>
                 <artifactId>commons-cli</artifactId>
-                <version>1.5.0</version>
+                <version>1.9.0</version>
             </dependency>
             <dependency>
                 <groupId>commons-codec</groupId>
                 <artifactId>commons-codec</artifactId>
-                <version>1.16.0</version>
+                <version>1.18.0</version>
             </dependency>
             <dependency>
                 <groupId>commons-fileupload</groupId>
             <dependency>
                 <groupId>commons-io</groupId>
                 <artifactId>commons-io</artifactId>
-                <version>2.17.0</version>
+                <version>2.18.0</version>
             </dependency>
             <dependency>
                 <groupId>commons-logging</groupId>
                 <artifactId>commons-logging</artifactId>
-                <version>1.3.4</version>
+                <version>1.3.5</version>
             </dependency>
             <dependency>
                 <groupId>commons-net</groupId>
                 <artifactId>commons-net</artifactId>
-                <version>3.9.0</version>
+                <version>3.11.1</version>
             </dependency>
             <dependency>
                 <groupId>io.micrometer</groupId>
             <dependency>
                 <groupId>io.micrometer</groupId>
                 <artifactId>micrometer-tracing-bridge-otel</artifactId>
-                <version>1.4.2</version>
+                <version>1.4.4</version>
             </dependency>
             <dependency>
                 <groupId>io.opentelemetry</groupId>
             <dependency>
                 <groupId>jakarta.activation</groupId>
                 <artifactId>jakarta.activation-api</artifactId>
-                <version>2.1.2</version>
+                <version>2.1.3</version>
             </dependency>
             <dependency>
                 <groupId>jakarta.annotation</groupId>
             <dependency>
                 <groupId>jakarta.validation</groupId>
                 <artifactId>jakarta.validation-api</artifactId>
-                <version>3.0.2</version>
+                <version>3.1.1</version>
             </dependency>
             <dependency>
                 <groupId>jakarta.ws.rs</groupId>
             <dependency>
                 <groupId>org.apache.commons</groupId>
                 <artifactId>commons-collections4</artifactId>
-                <version>4.5.0-M2</version>
+                <version>4.5.0-M3</version>
             </dependency>
             <dependency>
                 <groupId>org.apache.commons</groupId>
             <dependency>
                 <groupId>org.apache.commons</groupId>
                 <artifactId>commons-lang3</artifactId>
-                <version>3.14.0</version>
+                <version>3.17.0</version>
             </dependency>
             <dependency>
                 <groupId>org.apache.commons</groupId>
             <dependency>
                 <groupId>org.apache.commons</groupId>
                 <artifactId>commons-text</artifactId>
-                <version>1.10.0</version>
+                <version>1.13.0</version>
             </dependency>
             <dependency>
                 <groupId>org.apache.httpcomponents.client5</groupId>
             <dependency>
                 <groupId>org.apache.tomcat.embed</groupId>
                 <artifactId>tomcat-embed-core</artifactId>
-                <version>10.1.36</version>
+                <version>10.1.39</version>
             </dependency>
             <dependency>
                 <groupId>org.aspectj</groupId>
                 <artifactId>aspectjweaver</artifactId>
-                <version>1.9.22</version>
+                <version>1.9.23</version>
             </dependency>
             <dependency>
                 <groupId>org.bouncycastle</groupId>
                 <artifactId>bcpkix-fips</artifactId>
-                <version>2.0.7</version>
+                <version>2.1.9</version>
             </dependency>
             <dependency>
                 <groupId>org.codehaus.plexus</groupId>
             <dependency>
                 <groupId>org.hibernate.orm</groupId>
                 <artifactId>hibernate-core</artifactId>
-                <version>6.5.3.Final</version>
+                <version>6.6.13.Final</version>
             </dependency>
             <dependency>
                 <groupId>org.hibernate.validator</groupId>
                 <artifactId>hibernate-validator</artifactId>
-                <version>8.0.1.Final</version>
+                <version>8.0.2.Final</version>
             </dependency>
             <dependency>
                 <groupId>org.jetbrains.kotlin</groupId>
             <dependency>
                 <groupId>org.json</groupId>
                 <artifactId>json</artifactId>
-                <version>20240303</version>
+                <version>20250107</version>
             </dependency>
             <dependency>
                 <groupId>org.kie</groupId>
                 <artifactId>kie-ci</artifactId>
                 <version>${version.drools}</version>
             </dependency>
+            <dependency>
+                <groupId>org.openapitools</groupId>
+                <artifactId>jackson-databind-nullable</artifactId>
+                <version>0.2.6</version>
+            </dependency>
             <dependency>
                 <groupId>org.postgresql</groupId>
                 <artifactId>postgresql</artifactId>
-                <version>42.7.2</version>
+                <version>42.7.5</version>
             </dependency>
             <dependency>
                 <groupId>org.projectlombok</groupId>
                 <artifactId>lombok</artifactId>
-                <version>1.18.30</version>
+                <version>1.18.38</version>
             </dependency>
             <dependency>
                 <groupId>org.slf4j</groupId>
             <dependency>
                 <groupId>org.springdoc</groupId>
                 <artifactId>springdoc-openapi-starter-webmvc-ui</artifactId>
-                <version>2.8.5</version>
+                <version>2.8.6</version>
             </dependency>
             <dependency>
                 <groupId>org.springframework</groupId>