Upgrade springfox version to fix security issues 47/117247/1
authorRehanRaza <muhammad.rehan.raza@est.tech>
Fri, 29 Jan 2021 12:26:00 +0000 (13:26 +0100)
committerRehanRaza <muhammad.rehan.raza@est.tech>
Fri, 29 Jan 2021 16:57:07 +0000 (17:57 +0100)
Change-Id: I71b340cb63f3ea6f8814638517ad4482ed30c662
Issue-ID: CCSDK-3108
Signed-off-by: RehanRaza <muhammad.rehan.raza@est.tech>
a1-policy-management/pom.xml
a1-policy-management/src/main/java/org/onap/ccsdk/oran/a1policymanagementservice/SwaggerConfig.java

index cdb1bdb..d1f74dd 100644 (file)
@@ -35,7 +35,7 @@
     <properties>
         <java.version.source>11</java.version.source>
         <java.version.target>11</java.version.target>
-        <springfox.version>2.9.2</springfox.version>
+        <springfox.version>3.0.0</springfox.version>
         <!-- Do not change to version 3.0.0! Will break the generated json. -->
         <immutable.version>2.8.8</immutable.version>
         <sdk.version>1.1.6</sdk.version>
index 61c03ba..1197cc3 100644 (file)
@@ -82,9 +82,9 @@ public class SwaggerConfig extends WebMvcConfigurationSupport {
                 .select() //
                 .apis(RequestHandlerSelectors.any()) //
                 .paths(PathSelectors.any()) //
-                .paths(Predicates.not(PathSelectors.regex("/error"))) //
+                .paths(PathSelectors.regex("/error").negate()) //
                 // this endpoint is not implemented, but was visible for Swagger
-                .paths(Predicates.not(PathSelectors.regex("/actuator.*"))) //
+                .paths(PathSelectors.regex("/actuator.*").negate()) // 
                 // this endpoint is implemented by spring framework, exclude for now
                 .build();
     }