Security upgrade on dependencies. 71/138871/2
authoradheli.tavares <adheli.tavares@est.tech>
Fri, 30 Aug 2024 08:24:38 +0000 (09:24 +0100)
committerAdheli Tavares <adheli.tavares@est.tech>
Fri, 30 Aug 2024 12:35:13 +0000 (12:35 +0000)
Issue-ID: POLICY-5073
Change-Id: Ic009d55847a7a3b680de7b1edde0c645bd19055d
Signed-off-by: adheli.tavares <adheli.tavares@est.tech>
integration/pom.xml

index 2bd5f2f..c2a8587 100644 (file)
         <version.guava>33.0.0-jre</version.guava>
         <version.httpclient>5.3.1</version.httpclient>
         <version.io.prometheus>0.16.0</version.io.prometheus>
-        <version.jackson>2.16.1</version.jackson>
+        <version.jackson>2.17.2</version.jackson>
         <version.jacoco>0.8.11</version.jacoco>
         <version.jaxb>4.0.5</version.jaxb>
-        <version.jersey>3.1.5</version.jersey>
-        <version.jetty>11.0.20</version.jetty>
+        <version.jersey>3.1.8</version.jersey>
+        <version.jetty>11.0.23</version.jetty>
+        <version.jexl3>3.2.1</version.jexl3>
         <version.json-path>2.9.0</version.json-path>
         <version.json-schema-friend>0.12.4</version.json-schema-friend>
         <version.json-schema-validator>1.5.0</version.json-schema-validator>
         <version.jupiter>5.10.2</version.jupiter>
-        <version.kafka>3.6.1</version.kafka>
-        <version.kotlin>1.9.23</version.kotlin>
+        <version.kafka>3.8.0</version.kafka>
+        <version.kotlin>2.0.20</version.kotlin>
         <version.log4j>2.23.1</version.log4j>
-        <version.logback>1.5.6</version.logback>
+        <version.logback>1.5.7</version.logback>
         <version.maven-checkstyle-plugin>3.3.1</version.maven-checkstyle-plugin>
         <version.maven-remote-resources-plugin>3.1.0</version.maven-remote-resources-plugin>
-        <version.micrometer>1.11.10</version.micrometer>
+        <version.micrometer>1.13.3</version.micrometer>
         <version.mockito>5.5.0</version.mockito>
         <version.mockserver>5.15.0</version.mockserver>
         <version.netty>4.1.100.Final</version.netty>
         <version.nsa-cambria>1.2.1-oss</version.nsa-cambria>
         <version.nsa-sa-client>1.3.0-oss</version.nsa-sa-client>
-        <version.opentel>1.25.0</version.opentel>
+        <version.opentel>1.41.0</version.opentel>
         <version.plexus>3.5.0</version.plexus>
         <version.sdc-dist>2.1.1</version.sdc-dist>
         <version.sdc-tosca>1.9.0</version.sdc-tosca>
         <version.slf4j>2.0.13</version.slf4j>
-        <version.spring>6.1.11</version.spring>
-        <version.springboot>3.3.1</version.springboot>
-        <version.spring-security>6.3.1</version.spring-security>
+        <version.spring>6.1.12</version.spring>
+        <version.springboot>3.3.3</version.springboot>
+        <version.spring-security>6.3.3</version.spring-security>
         <version.sonar>3.11.0.3922</version.sonar>
         <version.swagger.codegen.v3>3.0.52</version.swagger.codegen.v3>
         <version.swagger.core.v3>2.2.20</version.swagger.core.v3>
-        <version.tomcat>10.1.19</version.tomcat>
+        <version.tomcat>10.1.28</version.tomcat>
         <surefireArgLine>
             --add-opens java.base/java.time=ALL-UNNAMED
             --add-opens java.base/java.util=ALL-UNNAMED
             <dependency>
                 <groupId>jakarta.servlet</groupId>
                 <artifactId>jakarta.servlet-api</artifactId>
-                <version>6.0.0</version>
+                <version>6.1.0</version>
             </dependency>
             <dependency>
                 <groupId>jakarta.validation</groupId>
             <dependency>
                 <groupId>jakarta.ws.rs</groupId>
                 <artifactId>jakarta.ws.rs-api</artifactId>
-                <version>3.1.0</version>
+                <version>4.0.0</version>
             </dependency>
             <dependency>
                 <groupId>jakarta.activation</groupId>
             <dependency>
                 <groupId>org.apache.commons</groupId>
                 <artifactId>commons-jexl3</artifactId>
-                <version>3.2.1</version>
+                <version>${version.jexl3}</version>
             </dependency>
             <dependency>
                 <groupId>commons-beanutils</groupId>
             <dependency>
                 <groupId>org.apache.tomcat.embed</groupId>
                 <artifactId>tomcat-embed-core</artifactId>
-                <version>10.1.25</version>
+                <version>10.1.28</version>
             </dependency>
             <dependency>
                 <groupId>org.springframework</groupId>
             <dependency>
                 <groupId>org.bouncycastle</groupId>
                 <artifactId>bcpkix-fips</artifactId>
-                <version>1.0.7</version>
+                <version>2.0.7</version>
             </dependency>
             <dependency>
                 <groupId>io.micrometer</groupId>
                 <artifactId>micrometer-tracing-bridge-otel</artifactId>
-                <version>1.1.8</version>
+                <version>1.3.3</version>
             </dependency>
             <dependency>
                 <groupId>io.opentelemetry.instrumentation</groupId>
                 <artifactId>opentelemetry-kafka-clients-2.6</artifactId>
-                <version>${version.opentel}-alpha</version>
+                <version>2.7.0-alpha</version>
             </dependency>
             <dependency>
                 <groupId>io.opentelemetry</groupId>
             <dependency>
                 <groupId>io.opentelemetry</groupId>
                 <artifactId>opentelemetry-sdk-extension-autoconfigure</artifactId>
-                <version>${version.opentel}-alpha</version>
+                <version>${version.opentel}</version>
             </dependency>
             <dependency>
                 <groupId>io.opentelemetry</groupId>