From 28da5021fad45b2c4da1bd1b7db794863e5ef7f3 Mon Sep 17 00:00:00 2001 From: Patrick Brady Date: Mon, 17 Sep 2018 12:52:55 -0700 Subject: [PATCH] Remove logback 1.1.3 security issue cdp-pal and eelf are the dependencies using logback-classic 1.1.3. Need to use exclusions option in pom file Change-Id: Id8f5817ec955e2b7b486bc0215c35541086606aa Signed-off-by: Patrick Brady Issue-ID: APPC-1018 --- .../appc-chef-adapter-bundle/pom.xml | 14 +++++++++++++- .../appc-iaas-adapter-bundle/pom.xml | 20 ++++++++++++++++++++ .../appc-netconf-adapter-bundle/pom.xml | 12 ++++++++++++ .../appc-rest-adapter-bundle/pom.xml | 12 ++++++++++++ .../appc-rest-healthcheck-adapter-bundle/pom.xml | 12 ++++++++++++ .../appc-ssh-adapter/appc-ssh-adapter-sshd/pom.xml | 11 +++++++++++ appc-config/appc-config-adaptor/provider/pom.xml | 12 +++++++++++- appc-config/appc-config-audit/provider/pom.xml | 11 +++++++++++ appc-config/appc-config-generator/provider/pom.xml | 12 +++++++++++- appc-config/appc-data-services/provider/pom.xml | 14 +++++++++++++- appc-config/appc-encryption-tool/provider/pom.xml | 11 +++++++++++ appc-config/appc-flow-controller/provider/pom.xml | 14 +++++++++++++- appc-core/appc-common-bundle/pom.xml | 13 ++++++++++++- .../appc-event-listener-bundle/pom.xml | 14 +++++++++++++- appc-inbound/appc-design-services/provider/pom.xml | 12 +++++++++++- appc-inbound/appc-interfaces-service/bundle/pom.xml | 12 +++++++++++- .../appc-lifecycle-management-core/pom.xml | 11 +++++++++++ appc-outbound/appc-aai-client/provider/pom.xml | 17 ++++++++++++++--- .../appc-network-inventory-client/provider/pom.xml | 11 +++++++++++ appc-parent/binding-parent/pom.xml | 2 +- pom.xml | 2 +- 21 files changed, 235 insertions(+), 14 deletions(-) diff --git a/appc-adapters/appc-chef-adapter/appc-chef-adapter-bundle/pom.xml b/appc-adapters/appc-chef-adapter/appc-chef-adapter-bundle/pom.xml index 417c70db8..105cf471b 100644 --- a/appc-adapters/appc-chef-adapter/appc-chef-adapter-bundle/pom.xml +++ b/appc-adapters/appc-chef-adapter/appc-chef-adapter-bundle/pom.xml @@ -93,8 +93,14 @@ com.att.cdp cdp-pal-common - compile ${cdp.pal.version} + compile + + + ch.qos.logback + logback-classic + + @@ -102,6 +108,12 @@ cdp-pal-openstack compile ${cdp.pal.version} + + + com.att.cdp + cdp-pal-common + + diff --git a/appc-adapters/appc-iaas-adapter/appc-iaas-adapter-bundle/pom.xml b/appc-adapters/appc-iaas-adapter/appc-iaas-adapter-bundle/pom.xml index 331773fc6..91cdd2663 100644 --- a/appc-adapters/appc-iaas-adapter/appc-iaas-adapter-bundle/pom.xml +++ b/appc-adapters/appc-iaas-adapter/appc-iaas-adapter-bundle/pom.xml @@ -48,11 +48,31 @@ + + + com.att.cdp + cdp-pal-common + compile + ${cdp.pal.version} + + + ch.qos.logback + logback-classic + + + + com.att.cdp cdp-pal-openstack compile ${cdp.pal.version} + + + com.att.cdp + cdp-pal-common + + diff --git a/appc-adapters/appc-netconf-adapter/appc-netconf-adapter-bundle/pom.xml b/appc-adapters/appc-netconf-adapter/appc-netconf-adapter-bundle/pom.xml index f87d7d139..a61659cb6 100644 --- a/appc-adapters/appc-netconf-adapter/appc-netconf-adapter-bundle/pom.xml +++ b/appc-adapters/appc-netconf-adapter/appc-netconf-adapter-bundle/pom.xml @@ -57,6 +57,12 @@ cdp-pal-common compile ${cdp.pal.version} + + + ch.qos.logback + logback-classic + + @@ -64,6 +70,12 @@ cdp-pal-openstack compile ${cdp.pal.version} + + + com.att.cdp + cdp-pal-common + + diff --git a/appc-adapters/appc-rest-adapter/appc-rest-adapter-bundle/pom.xml b/appc-adapters/appc-rest-adapter/appc-rest-adapter-bundle/pom.xml index b67b3bd5c..8c666b669 100644 --- a/appc-adapters/appc-rest-adapter/appc-rest-adapter-bundle/pom.xml +++ b/appc-adapters/appc-rest-adapter/appc-rest-adapter-bundle/pom.xml @@ -66,6 +66,12 @@ cdp-pal-common compile ${cdp.pal.version} + + + ch.qos.logback + logback-classic + + @@ -73,6 +79,12 @@ cdp-pal-openstack compile ${cdp.pal.version} + + + com.att.cdp + cdp-pal-common + + diff --git a/appc-adapters/appc-rest-healthcheck-adapter/appc-rest-healthcheck-adapter-bundle/pom.xml b/appc-adapters/appc-rest-healthcheck-adapter/appc-rest-healthcheck-adapter-bundle/pom.xml index 0e0ce5104..517553218 100644 --- a/appc-adapters/appc-rest-healthcheck-adapter/appc-rest-healthcheck-adapter-bundle/pom.xml +++ b/appc-adapters/appc-rest-healthcheck-adapter/appc-rest-healthcheck-adapter-bundle/pom.xml @@ -72,12 +72,24 @@ com.att.cdp cdp-pal-common compile + + + ch.qos.logback + logback-classic + + com.att.cdp cdp-pal-openstack compile + + + com.att.cdp + cdp-pal-common + + diff --git a/appc-adapters/appc-ssh-adapter/appc-ssh-adapter-sshd/pom.xml b/appc-adapters/appc-ssh-adapter/appc-ssh-adapter-sshd/pom.xml index 4d00b5763..c65856655 100644 --- a/appc-adapters/appc-ssh-adapter/appc-ssh-adapter-sshd/pom.xml +++ b/appc-adapters/appc-ssh-adapter/appc-ssh-adapter-sshd/pom.xml @@ -58,9 +58,20 @@ provided 2.0.0 + + ch.qos.logback + logback-classic + ${logback.version} + com.att.eelf eelf-core + + + ch.qos.logback + logback-classic + + junit diff --git a/appc-config/appc-config-adaptor/provider/pom.xml b/appc-config/appc-config-adaptor/provider/pom.xml index aa5e24f51..4fbf5a5e7 100644 --- a/appc-config/appc-config-adaptor/provider/pom.xml +++ b/appc-config/appc-config-adaptor/provider/pom.xml @@ -70,10 +70,20 @@ mockito-core test - + + ch.qos.logback + logback-classic + ${logback.version} + com.att.eelf eelf-core + + + ch.qos.logback + logback-classic + + diff --git a/appc-config/appc-config-audit/provider/pom.xml b/appc-config/appc-config-audit/provider/pom.xml index 3babf6d6f..bb6629200 100644 --- a/appc-config/appc-config-audit/provider/pom.xml +++ b/appc-config/appc-config-audit/provider/pom.xml @@ -73,9 +73,20 @@ commons-io commons-io + + ch.qos.logback + logback-classic + ${logback.version} + com.att.eelf eelf-core + + + ch.qos.logback + logback-classic + + org.apache.commons diff --git a/appc-config/appc-config-generator/provider/pom.xml b/appc-config/appc-config-generator/provider/pom.xml index 271873581..fd5eacdc1 100644 --- a/appc-config/appc-config-generator/provider/pom.xml +++ b/appc-config/appc-config-generator/provider/pom.xml @@ -94,10 +94,20 @@ commons-collections 3.2.2 - + + ch.qos.logback + logback-classic + ${logback.version} + com.att.eelf eelf-core + + + ch.qos.logback + logback-classic + + diff --git a/appc-config/appc-data-services/provider/pom.xml b/appc-config/appc-data-services/provider/pom.xml index 92468db81..0b5676ea0 100644 --- a/appc-config/appc-data-services/provider/pom.xml +++ b/appc-config/appc-data-services/provider/pom.xml @@ -62,10 +62,21 @@ commons-io commons-io + + ch.qos.logback + logback-classic + ${logback.version} + com.att.eelf eelf-core + + + ch.qos.logback + logback-classic + + @@ -138,7 +149,8 @@ appc-config-data-services org.onap.appc.data.services.AppcDataServiceActivator org.onap.appc.data.services - * + groovy.lang;resolution:=optional, + org.codehaus.groovy.*;resolution:=optional,* eelf-core,logback-core,logback-classic * diff --git a/appc-config/appc-encryption-tool/provider/pom.xml b/appc-config/appc-encryption-tool/provider/pom.xml index 2866797ee..d9ffca478 100644 --- a/appc-config/appc-encryption-tool/provider/pom.xml +++ b/appc-config/appc-encryption-tool/provider/pom.xml @@ -65,9 +65,20 @@ org.apache.commons commons-lang3 + + ch.qos.logback + logback-classic + ${logback.version} + com.att.eelf eelf-core + + + ch.qos.logback + logback-classic + + commons-configuration diff --git a/appc-config/appc-flow-controller/provider/pom.xml b/appc-config/appc-flow-controller/provider/pom.xml index f3cd09b89..065b3be22 100644 --- a/appc-config/appc-flow-controller/provider/pom.xml +++ b/appc-config/appc-flow-controller/provider/pom.xml @@ -68,9 +68,20 @@ com.fasterxml.jackson.dataformat jackson-dataformat-yaml + + ch.qos.logback + logback-classic + ${logback.version} + com.att.eelf eelf-core + + + ch.qos.logback + logback-classic + + org.onap.ccsdk.sli.adaptors @@ -141,7 +152,8 @@ org.onap.appc.flow.controller org.onap.appc.flow.controller.FlowControllerActivator org.onap.appc.flow.controller - * + groovy.lang;resolution:=optional, + org.codehaus.groovy.*;resolution:=optional,* eelf-core,logback-core,logback-classic * diff --git a/appc-core/appc-common-bundle/pom.xml b/appc-core/appc-common-bundle/pom.xml index 0f72a1620..07300f53f 100644 --- a/appc-core/appc-common-bundle/pom.xml +++ b/appc-core/appc-common-bundle/pom.xml @@ -30,9 +30,20 @@ + + ch.qos.logback + logback-classic + ${logback.version} + com.att.eelf eelf-core + + + ch.qos.logback + logback-classic + + org.slf4j @@ -157,4 +168,4 @@ - \ No newline at end of file + diff --git a/appc-event-listener/appc-event-listener-bundle/pom.xml b/appc-event-listener/appc-event-listener-bundle/pom.xml index abd664e23..426fbd924 100644 --- a/appc-event-listener/appc-event-listener-bundle/pom.xml +++ b/appc-event-listener/appc-event-listener-bundle/pom.xml @@ -41,10 +41,21 @@ ${project.version} --> + + ch.qos.logback + logback-classic + ${logback.version} + com.att.eelf eelf-core - + + + ch.qos.logback + logback-classic + + + org.onap.appc appc-common-bundle @@ -119,6 +130,7 @@ org.mockito mockito-core + test diff --git a/appc-inbound/appc-design-services/provider/pom.xml b/appc-inbound/appc-design-services/provider/pom.xml index f4ffee6fb..7206230ca 100755 --- a/appc-inbound/appc-design-services/provider/pom.xml +++ b/appc-inbound/appc-design-services/provider/pom.xml @@ -113,10 +113,20 @@ sal-binding-broker-impl test - + + ch.qos.logback + logback-classic + ${logback.version} + com.att.eelf eelf-core + + + ch.qos.logback + logback-classic + + org.onap.ccsdk.sli.adaptors diff --git a/appc-inbound/appc-interfaces-service/bundle/pom.xml b/appc-inbound/appc-interfaces-service/bundle/pom.xml index bf85243db..d2172865b 100644 --- a/appc-inbound/appc-interfaces-service/bundle/pom.xml +++ b/appc-inbound/appc-interfaces-service/bundle/pom.xml @@ -110,10 +110,20 @@ sal-binding-broker-impl test - + + ch.qos.logback + logback-classic + ${logback.version} + com.att.eelf eelf-core + + + ch.qos.logback + logback-classic + + com.sun.jersey diff --git a/appc-lifecycle-management/appc-lifecycle-management-core/pom.xml b/appc-lifecycle-management/appc-lifecycle-management-core/pom.xml index c76269293..e9bf49ae3 100644 --- a/appc-lifecycle-management/appc-lifecycle-management-core/pom.xml +++ b/appc-lifecycle-management/appc-lifecycle-management-core/pom.xml @@ -70,9 +70,20 @@ state-machine-lib ${project.version} + + ch.qos.logback + logback-classic + ${logback.version} + com.att.eelf eelf-core + + + ch.qos.logback + logback-classic + + diff --git a/appc-outbound/appc-aai-client/provider/pom.xml b/appc-outbound/appc-aai-client/provider/pom.xml index 126e46136..11d42210c 100755 --- a/appc-outbound/appc-aai-client/provider/pom.xml +++ b/appc-outbound/appc-aai-client/provider/pom.xml @@ -60,14 +60,24 @@ commons-io 2.5 - + org.apache.commons commons-lang3 - + + ch.qos.logback + logback-classic + ${logback.version} + com.att.eelf eelf-core + + + ch.qos.logback + logback-classic + + @@ -135,7 +145,8 @@ org.onap.appc.aai.client org.onap.appc.aai.client.AppcAaiClientActivator org.onap.appc.aai.client,org.onap.appc.aai.client.* - * + groovy.lang;resolution:=optional, + org.codehaus.groovy.*;resolution:=optional,* * eelf-core,logback-core,logback-classic diff --git a/appc-outbound/appc-network-inventory-client/provider/pom.xml b/appc-outbound/appc-network-inventory-client/provider/pom.xml index e2edfbac2..b91cbe6d7 100755 --- a/appc-outbound/appc-network-inventory-client/provider/pom.xml +++ b/appc-outbound/appc-network-inventory-client/provider/pom.xml @@ -48,9 +48,20 @@ commons-io commons-io + + ch.qos.logback + logback-classic + ${logback.version} + com.att.eelf eelf-core + + + ch.qos.logback + logback-classic + + com.sun.jersey diff --git a/appc-parent/binding-parent/pom.xml b/appc-parent/binding-parent/pom.xml index 6252b8e3b..991e3ab21 100644 --- a/appc-parent/binding-parent/pom.xml +++ b/appc-parent/binding-parent/pom.xml @@ -55,7 +55,7 @@ limitations under the License. 4.4 3.4 4.5.1 - 1.2.0 + 1.2.3 1.1.0 1.3.0 diff --git a/pom.xml b/pom.xml index 15bdd0796..4472c28ce 100644 --- a/pom.xml +++ b/pom.xml @@ -377,7 +377,7 @@ limitations under the License. ch.qos.logback logback-core - ${logback.version} + ${logback.version} compile -- 2.16.6