Fix usecase-ui security risks 62/87862/1
authorguochuyicmri <guochuyi@chinamobile.com>
Thu, 16 May 2019 11:44:28 +0000 (19:44 +0800)
committerguochuyicmri <guochuyi@chinamobile.com>
Thu, 16 May 2019 11:44:33 +0000 (19:44 +0800)
Change-Id: Iba150e755d60c181caa20b8b1ef721a19ca97631
Issue-ID: USECASEUI-258
Signed-off-by: guochuyicmri <guochuyi@chinamobile.com>
pom.xml
server/pom.xml

diff --git a/pom.xml b/pom.xml
index 39d5a5b..3921d55 100644 (file)
--- a/pom.xml
+++ b/pom.xml
         <siteNexusPath>content/sites/site/${project.groupId}/${project.artifactId}/${project.version}/</siteNexusPath>
     </properties>
 
-    <distributionManagement>
-        <repository>
-            <id>onap-releases</id>
-            <url>${nexusproxy}/${releaseNexusPath}</url>
-        </repository>
-        <snapshotRepository>
-            <id>onap-snapshots</id>
-            <url>${nexusproxy}/${snapshotNexusPath}</url>
-        </snapshotRepository>
-        <site>
-            <id>onap-site</id>
-            <url>dav:${nexusproxy}${siteNexusPath}</url>
-        </site>
-    </distributionManagement>
-
     <!-- Specify the repositories here to avoid coordination of ~/.m2/settings.xml 
         files among developers. Use values (not properties) so oparent can be resolved. -->
     <repositories>
index 1e062d0..e597dbf 100644 (file)
@@ -95,6 +95,7 @@
         <dependency>
             <groupId>org.springframework.data</groupId>
             <artifactId>spring-data-rest-hal-browser</artifactId>
+            <version>2.6.21.RELEASE</version>
         </dependency>
         <dependency>
             <groupId>org.springframework.boot</groupId>
         </dependency>
 
         <!-- security vulnerabilities -->
+        <dependency>
+            <groupId>org.apache.tomcat.embed</groupId>
+            <artifactId>tomcat-embed-websocket</artifactId>
+            <version>8.5.32</version>
+        </dependency>
         <dependency>
             <groupId>ch.qos.logback</groupId>
             <artifactId>logback-classic</artifactId>
             <version>1.1.1</version>
         </dependency>
 
-        <dependency>
-            <groupId>com.google.guava</groupId>
-            <artifactId>guava</artifactId>
-            <version>23.0</version>
-        </dependency>
-
         <dependency>
             <groupId>org.onap.msb.java-sdk</groupId>
             <artifactId>msb-java-sdk</artifactId>