From 54f90a51609b72e955c5c8de09990d0d3941e595 Mon Sep 17 00:00:00 2001 From: Fiete Ostkamp Date: Mon, 14 Jul 2025 09:37:04 +0200 Subject: [PATCH] Update vulnerable dependencies - consistently use the same logback version everywhere (1.2.10 -> 1.2.11) - consistently uuse the same kafka-clients version everywhere (3.3.1 -> 3.3.2) - declare ehcache dependency in aai-client pom instead of common since it is only used there Issue-ID: SO-4199 Change-Id: Id8b5c6c061e6f0921e45fb6763fe2384f0315fe4 Signed-off-by: Fiete Ostkamp --- asdc-controller/pom.xml | 1 - bpmn/pom.xml | 3 +-- bpmn/so-bpmn-infrastructure-common/pom.xml | 1 - common/pom.xml | 13 +++++++------ graph-inventory/aai-client/pom.xml | 4 ++++ pom.xml | 1 + 6 files changed, 13 insertions(+), 10 deletions(-) diff --git a/asdc-controller/pom.xml b/asdc-controller/pom.xml index a2f4a7494c..febccbe578 100644 --- a/asdc-controller/pom.xml +++ b/asdc-controller/pom.xml @@ -16,7 +16,6 @@ 1.6.5 1.5.1 2.0.0 - 3.3.2 ${project.artifactId}-${project.version} diff --git a/bpmn/pom.xml b/bpmn/pom.xml index c0a3192189..6d2ac6e5d6 100644 --- a/bpmn/pom.xml +++ b/bpmn/pom.xml @@ -19,9 +19,8 @@ 2.4.0 UTF-8 UTF-8 - 3.0.2 - 1.2.10 + 3.0.2 MSOCoreBPMN diff --git a/bpmn/so-bpmn-infrastructure-common/pom.xml b/bpmn/so-bpmn-infrastructure-common/pom.xml index 94412a290b..cfdb67b61f 100644 --- a/bpmn/so-bpmn-infrastructure-common/pom.xml +++ b/bpmn/so-bpmn-infrastructure-common/pom.xml @@ -220,7 +220,6 @@ ch.qos.logback logback-core - ${logback-core.version} org.slf4j diff --git a/common/pom.xml b/common/pom.xml index 9b8b06339c..894bb15f47 100644 --- a/common/pom.xml +++ b/common/pom.xml @@ -37,6 +37,7 @@ com.jayway.jsonpath json-path + 2.5.0 org.hibernate @@ -145,6 +146,10 @@ io.springfox springfox-boot-starter + + org.apache.kafka + kafka-clients + @@ -238,11 +243,7 @@ javax.cache cache-api - 1.0.0 - - - org.ehcache - ehcache + 1.1.0 org.springframework.cloud @@ -252,7 +253,7 @@ org.apache.kafka kafka-clients - 3.3.1 + ${kafka-clients.version} uk.org.webcompere diff --git a/graph-inventory/aai-client/pom.xml b/graph-inventory/aai-client/pom.xml index 193a33b6b1..b1e7a21642 100644 --- a/graph-inventory/aai-client/pom.xml +++ b/graph-inventory/aai-client/pom.xml @@ -139,6 +139,10 @@ compile true + + org.ehcache + ehcache + org.apache.cxf cxf-rt-rs-client diff --git a/pom.xml b/pom.xml index a62a4b6340..baac65402d 100644 --- a/pom.xml +++ b/pom.xml @@ -79,6 +79,7 @@ 2.14.3 1.25.0 1.2.11 + 3.3.2 -- 2.16.6