From: Fiete Ostkamp Date: Sun, 1 Jun 2025 09:26:36 +0000 (+0200) Subject: Update vulnerable dependencies X-Git-Tag: 2.1.0^0 X-Git-Url: https://gerrit.onap.org/r/gitweb?a=commitdiff_plain;h=73dbfc31de1be9747df2b93b6234cfcc2e810a2d;p=aai%2Fsparky-be.git Update vulnerable dependencies - update logback (1.2.3 -> 1.2.13) - update guava (26.0-jre -> 33.4.8-jre) - update dom4j (2.1.1 -> 2.1.4) - update gson (2.8.5 -> 2.8.9) - update camel (2.21.1 -> 2.21.5) - make junit test scoped Issue-ID: AAI-4166 Change-Id: Ifee29bd8b92ecec68f1075db63a34f134806a790 Signed-off-by: Fiete Ostkamp --- diff --git a/sparkybe-onap-application/pom.xml b/sparkybe-onap-application/pom.xml index c21e070..079ab42 100644 --- a/sparkybe-onap-application/pom.xml +++ b/sparkybe-onap-application/pom.xml @@ -21,12 +21,15 @@ 9517 8000 https://nexus.onap.org - 2.21.1 + 2.21.5 ${basedir}/ 1.12.10 /content/sites/site/org/onap/aai/sparky-be/${project.artifactId}/${project.version} https://nexus.onap.org 1.5.21.RELEASE + 1.2.13 + 33.4.8-jre + 2.8.9 onap sparky-be @@ -61,7 +64,22 @@ ch.qos.logback logback-classic - 1.2.13 + ${logback.version} + + + ch.qos.logback + logback-core + ${logback.version} + + + com.google.guava + guava + ${guava.version} + + + com.google.code.gson + gson + ${gson.version} @@ -95,6 +113,18 @@ org.springframework.boot spring-boot-starter-test + + + junit + junit + + + + + + junit + junit + test @@ -189,7 +219,6 @@ com.google.guava guava - 33.3.1-jre @@ -202,7 +231,7 @@ org.dom4j dom4j provided - 2.1.1 + 2.1.4 diff --git a/sparkybe-onap-application/src/test/java/org/onap/aai/sparky/aggregatevnf/AggregateSummaryProcessorTest.java b/sparkybe-onap-application/src/test/java/org/onap/aai/sparky/aggregatevnf/AggregateSummaryProcessorTest.java index 7c325b3..6dbe9e8 100644 --- a/sparkybe-onap-application/src/test/java/org/onap/aai/sparky/aggregatevnf/AggregateSummaryProcessorTest.java +++ b/sparkybe-onap-application/src/test/java/org/onap/aai/sparky/aggregatevnf/AggregateSummaryProcessorTest.java @@ -72,7 +72,7 @@ public class AggregateSummaryProcessorTest { @Value("${schema.ingest.file}") String schemaIngestFileLocation; @Test - public void someTest() throws RestClientException, JsonProcessingException { + public void thatAggregateSummaryWorks() throws RestClientException, JsonProcessingException { when(searchServiceAdapter.doPost(Mockito.any(), Mockito.any())).thenReturn(operationResult); when(operationResult.wasSuccessful()).thenReturn(true); diff --git a/sparkybe-onap-service/pom.xml b/sparkybe-onap-service/pom.xml index 6e293c4..f4bb53c 100644 --- a/sparkybe-onap-service/pom.xml +++ b/sparkybe-onap-service/pom.xml @@ -20,7 +20,7 @@ 9517 8000 https://nexus.onap.org - 2.21.1 + 2.21.5 ${basedir}/ 1.4.1 1.12.10 @@ -28,6 +28,9 @@ https://neexus.onap.org 0.53 1.5.22.RELEASE + 33.4.8-jre + 2.8.9 + 1.2.13 @@ -51,7 +54,17 @@ ch.qos.logback logback-classic - 1.2.3 + ${logback.version} + + + ch.qos.logback + logback-core + ${logback.version} + + + com.google.code.gson + gson + ${gson.version} @@ -134,7 +147,6 @@ some of the depedencies should probably have a scope of provided so they don't a commons-io - org.eclipse.jetty jetty-util @@ -146,32 +158,16 @@ some of the depedencies should probably have a scope of provided so they don't a camel-servlet-starter - commons-cli commons-cli 1.2 - - - - - - - - com.google.guava guava - 26.0-jre + ${guava.version} @@ -186,7 +182,7 @@ some of the depedencies should probably have a scope of provided so they don't a org.dom4j dom4j provided - 2.1.1 + 2.1.4 @@ -213,11 +209,11 @@ some of the depedencies should probably have a scope of provided so they don't a ${version.aai-schema} - - org.onap.aai.aai-common - aai-schema-ingest - ${version.aai.aai-schema-ingest} - + + org.onap.aai.aai-common + aai-schema-ingest + ${version.aai.aai-schema-ingest} + org.slf4j slf4j-log4j12 @@ -230,8 +226,8 @@ some of the depedencies should probably have a scope of provided so they don't a org.powermock powermock-api-mockito - - + + org.onap.aai @@ -239,7 +235,6 @@ some of the depedencies should probably have a scope of provided so they don't a 1.3.0 - org.restlet.jee org.restlet.ext.servlet