Security uplifts 03/141303/1
authoradheli.tavares <adheli.tavares@est.tech>
Mon, 16 Jun 2025 16:40:37 +0000 (17:40 +0100)
committeradheli.tavares <adheli.tavares@est.tech>
Mon, 16 Jun 2025 16:41:26 +0000 (17:41 +0100)
- maven plugins
- spring
- tomcat embed

Issue-ID: POLICY-5394
Change-Id: I0503f7969c9f85a4bfb124799b0f0fb848aed92e
Signed-off-by: adheli.tavares <adheli.tavares@est.tech>
integration/pom.xml
pom.xml

index 0ae6d78..838dff4 100644 (file)
         <version.sdc-dist>2.1.1</version.sdc-dist>
         <version.sdc-tosca>1.9.0</version.sdc-tosca>
         <version.slf4j>2.0.17</version.slf4j>
-        <version.spring>6.2.7</version.spring>
-        <version.springboot>3.4.6</version.springboot>
-        <version.spring-data>3.4.6</version.spring-data>
-        <version.spring-security>6.4.6</version.spring-security>
+        <version.spring>6.2.8</version.spring>
+        <version.springboot>3.5.0</version.springboot>
+        <version.spring-data>3.5.1</version.spring-data>
+        <version.spring-security>6.5.0</version.spring-security>
         <version.sonar>3.11.0.3922</version.sonar>
         <version.swagger.codegen.v3>3.0.68</version.swagger.codegen.v3>
         <version.swagger.core.v3>2.2.29</version.swagger.core.v3>
             <dependency>
                 <groupId>org.apache.tomcat.embed</groupId>
                 <artifactId>tomcat-embed-core</artifactId>
-                <version>10.1.41</version>
+                <version>11.0.8</version>
             </dependency>
             <dependency>
                 <groupId>org.aspectj</groupId>
                     <plugin>
                         <groupId>org.owasp</groupId>
                         <artifactId>dependency-check-maven</artifactId>
-                        <version>10.0.3</version>
                         <executions>
                             <execution>
                                 <goals>
             <extension>
                 <groupId>org.apache.maven.archetype</groupId>
                 <artifactId>archetype-packaging</artifactId>
-                <version>3.2.1</version>
+                <version>3.4.0</version>
             </extension>
         </extensions>
         <pluginManagement>
                 <plugin>
                     <groupId>io.github.git-commit-id</groupId>
                     <artifactId>git-commit-id-maven-plugin</artifactId>
-                    <version>6.0.0</version>
+                    <version>9.0.2</version>
                     <executions>
                         <execution>
                             <goals>
                 <plugin>
                     <groupId>org.apache.maven.plugins</groupId>
                     <artifactId>maven-archetype-plugin</artifactId>
-                    <version>3.2.1</version>
+                    <version>3.4.0</version>
                 </plugin>
                 <plugin>
                     <groupId>org.apache.maven.plugins</groupId>
                 <plugin>
                     <groupId>org.apache.maven.plugins</groupId>
                     <artifactId>maven-dependency-plugin</artifactId>
-                    <version>3.6.0</version>
+                    <version>3.8.1</version>
                 </plugin>
                 <plugin>
                     <groupId>org.apache.maven.plugins</groupId>
                 <plugin>
                     <groupId>org.apache.maven.plugins</groupId>
                     <artifactId>maven-surefire-plugin</artifactId>
-                    <version>3.1.2</version>
+                    <version>3.5.3</version>
                 </plugin>
                 <plugin>
                     <groupId>org.sonarsource.scanner.maven</groupId>
diff --git a/pom.xml b/pom.xml
index 3bcfecd..534da50 100644 (file)
--- a/pom.xml
+++ b/pom.xml
@@ -95,7 +95,7 @@
             <plugin>
                 <groupId>org.apache.maven.plugins</groupId>
                 <artifactId>maven-compiler-plugin</artifactId>
-                <version>3.11.0</version>
+                <version>3.14.0</version>
                 <configuration>
                     <encoding>${project.build.sourceEncoding}</encoding>
                     <release>${maven.compiler.release}</release>
                 <artifactId>maven-site-plugin</artifactId>
                 <version>3.21.0</version>
             </plugin>
+            <plugin>
+                <groupId>org.owasp</groupId>
+                <artifactId>dependency-check-maven</artifactId>
+                <version>10.0.3</version>
+            </plugin>
         </plugins>
     </build>