resolving logback-classic 1.13 from security issue 61/61161/4
authorTaka Cho <tc012c@att.com>
Sat, 18 Aug 2018 19:56:57 +0000 (15:56 -0400)
committerPatrick Brady <pb071s@att.com>
Mon, 20 Aug 2018 16:14:15 +0000 (16:14 +0000)
cdp-pal and eelf are the jar using logback-classic 1.1.3.
need to use exclusions option in pom file

Issue-ID: APPC-1018
Change-Id: I00b41f9c366a5ead3f4205cd6fa6b9eb74599767
Signed-off-by: Taka Cho <tc012c@att.com>
20 files changed:
appc-adapters/appc-chef-adapter/appc-chef-adapter-bundle/pom.xml
appc-adapters/appc-iaas-adapter/appc-iaas-adapter-bundle/pom.xml
appc-adapters/appc-netconf-adapter/appc-netconf-adapter-bundle/pom.xml
appc-adapters/appc-rest-adapter/appc-rest-adapter-bundle/pom.xml
appc-adapters/appc-rest-healthcheck-adapter/appc-rest-healthcheck-adapter-bundle/pom.xml
appc-adapters/appc-ssh-adapter/appc-ssh-adapter-sshd/pom.xml
appc-config/appc-config-adaptor/provider/pom.xml
appc-config/appc-config-audit/provider/pom.xml
appc-config/appc-config-generator/provider/pom.xml
appc-config/appc-data-services/provider/pom.xml
appc-config/appc-encryption-tool/provider/pom.xml
appc-config/appc-flow-controller/provider/pom.xml
appc-core/appc-common-bundle/pom.xml
appc-event-listener/appc-event-listener-bundle/pom.xml
appc-inbound/appc-design-services/provider/pom.xml
appc-inbound/appc-interfaces-service/bundle/pom.xml
appc-lifecycle-management/appc-lifecycle-management-core/pom.xml
appc-outbound/appc-aai-client/provider/pom.xml
appc-outbound/appc-network-inventory-client/provider/pom.xml
pom.xml

index bc98466..41b3de6 100644 (file)
         <dependency>
             <groupId>com.att.cdp</groupId>
             <artifactId>cdp-pal-common</artifactId>
-            <scope>compile</scope>
             <version>${cdp.pal.version}</version>
+            <scope>compile</scope>
+            <exclusions>
+                <exclusion>
+                  <groupId>ch.qos.logback</groupId>
+                  <artifactId>logback-classic</artifactId>
+                </exclusion>
+            </exclusions>
         </dependency>
 
         <dependency>
             <artifactId>cdp-pal-openstack</artifactId>
             <scope>compile</scope>
             <version>${cdp.pal.version}</version>
+            <exclusions>
+                  <exclusion>
+                       <groupId>com.att.cdp</groupId>
+                       <artifactId>cdp-pal-common</artifactId>
+                  </exclusion>
+            </exclusions>
         </dependency>
 
         <dependency>
index 331773f..91cdd26 100644 (file)
             </exclusions>
         </dependency>
 
+
+        <dependency>
+            <groupId>com.att.cdp</groupId>
+            <artifactId>cdp-pal-common</artifactId>
+            <scope>compile</scope>
+            <version>${cdp.pal.version}</version>
+            <exclusions>
+                <exclusion>
+                  <groupId>ch.qos.logback</groupId>
+                  <artifactId>logback-classic</artifactId>
+                </exclusion>
+            </exclusions>
+        </dependency>
+
         <dependency>
             <groupId>com.att.cdp</groupId>
             <artifactId>cdp-pal-openstack</artifactId>
             <scope>compile</scope>
             <version>${cdp.pal.version}</version>
+            <exclusions>
+                  <exclusion>
+                       <groupId>com.att.cdp</groupId>
+                       <artifactId>cdp-pal-common</artifactId>
+                  </exclusion>
+            </exclusions>
         </dependency>
 
         <dependency>
index f87d7d1..a61659c 100644 (file)
             <artifactId>cdp-pal-common</artifactId>
             <scope>compile</scope>
             <version>${cdp.pal.version}</version>
+            <exclusions>
+                <exclusion>
+                  <groupId>ch.qos.logback</groupId>
+                  <artifactId>logback-classic</artifactId>
+                </exclusion>
+            </exclusions>
         </dependency>
 
         <dependency>
             <artifactId>cdp-pal-openstack</artifactId>
             <scope>compile</scope>
             <version>${cdp.pal.version}</version>
+            <exclusions>
+                  <exclusion>
+                       <groupId>com.att.cdp</groupId>
+                       <artifactId>cdp-pal-common</artifactId>
+                  </exclusion>
+            </exclusions>
         </dependency>
 
         <dependency>
index b67b3bd..8c666b6 100644 (file)
                        <artifactId>cdp-pal-common</artifactId>
                        <scope>compile</scope>
                         <version>${cdp.pal.version}</version>
+                        <exclusions>
+                            <exclusion>
+                                 <groupId>ch.qos.logback</groupId>
+                                 <artifactId>logback-classic</artifactId>
+                            </exclusion>
+                        </exclusions>
                </dependency>
 
                <dependency>
                        <artifactId>cdp-pal-openstack</artifactId>
                        <scope>compile</scope>
                         <version>${cdp.pal.version}</version>
+                        <exclusions>
+                            <exclusion>
+                                 <groupId>com.att.cdp</groupId>
+                                 <artifactId>cdp-pal-common</artifactId>
+                            </exclusion>
+                        </exclusions>
                </dependency>
 
                <dependency>
index 8361f46..054f7fb 100644 (file)
             <groupId>com.att.cdp</groupId>
             <artifactId>cdp-pal-common</artifactId>
             <scope>compile</scope>
+            <exclusions>
+                <exclusion>
+                  <groupId>ch.qos.logback</groupId>
+                  <artifactId>logback-classic</artifactId>
+                </exclusion>
+            </exclusions>
         </dependency>
 
         <dependency>
             <groupId>com.att.cdp</groupId>
             <artifactId>cdp-pal-openstack</artifactId>
             <scope>compile</scope>
+            <exclusions>
+                  <exclusion>
+                       <groupId>com.att.cdp</groupId>
+                       <artifactId>cdp-pal-common</artifactId>
+                  </exclusion>
+            </exclusions>
         </dependency>
 
         <dependency>
index 4d00b57..c658566 100644 (file)
             <scope>provided</scope>
             <version>2.0.0</version>
         </dependency>
+        <dependency>
+         <groupId>ch.qos.logback</groupId>
+         <artifactId>logback-classic</artifactId>
+        <version>${logback.version}</version>
+        </dependency>
         <dependency>
             <groupId>com.att.eelf</groupId>
             <artifactId>eelf-core</artifactId>
+            <exclusions>
+                 <exclusion>
+                      <groupId>ch.qos.logback</groupId>
+                      <artifactId>logback-classic</artifactId>
+                 </exclusion>
+            </exclusions>
         </dependency>
         <dependency>
             <groupId>junit</groupId>
index a5c90e4..859b24a 100644 (file)
                        <artifactId>mockito-core</artifactId>
                        <scope>test</scope>
                </dependency>
-
+        <dependency>
+         <groupId>ch.qos.logback</groupId>
+         <artifactId>logback-classic</artifactId>
+        <version>${logback.version}</version>
+        </dependency>
         <dependency>
             <groupId>com.att.eelf</groupId>
             <artifactId>eelf-core</artifactId>
+            <exclusions>
+                <exclusion>
+                    <groupId>ch.qos.logback</groupId>
+                    <artifactId>logback-classic</artifactId>
+                </exclusion>
+            </exclusions>
         </dependency>
 
         <dependency>
index 59baa05..e9c6b90 100644 (file)
             <groupId>commons-io</groupId>
             <artifactId>commons-io</artifactId>
         </dependency>
+        <dependency>
+         <groupId>ch.qos.logback</groupId>
+         <artifactId>logback-classic</artifactId>
+        <version>${logback.version}</version>
+        </dependency>
         <dependency>
             <groupId>com.att.eelf</groupId>
             <artifactId>eelf-core</artifactId>
+            <exclusions>
+                <exclusion>
+                     <groupId>ch.qos.logback</groupId>
+                     <artifactId>logback-classic</artifactId>
+                </exclusion>
+            </exclusions>
         </dependency>
         <dependency>
             <groupId>org.apache.commons</groupId>
index 2718735..fd5eacd 100644 (file)
                 <artifactId>commons-collections</artifactId>
                 <version>3.2.2</version>
           </dependency>
-
+         <dependency>
+           <groupId>ch.qos.logback</groupId>
+           <artifactId>logback-classic</artifactId>
+          <version>${logback.version}</version>
+        </dependency>
         <dependency>
             <groupId>com.att.eelf</groupId>
             <artifactId>eelf-core</artifactId>
+            <exclusions>
+                 <exclusion>
+                      <groupId>ch.qos.logback</groupId>
+                      <artifactId>logback-classic</artifactId>
+                 </exclusion>
+            </exclusions>
         </dependency>
 
         <dependency>
index 92468db..b383133 100644 (file)
                        <groupId>commons-io</groupId>
                        <artifactId>commons-io</artifactId>
                </dependency>
+                <dependency>
+                     <groupId>ch.qos.logback</groupId>
+                     <artifactId>logback-classic</artifactId>
+                    <version>${logback.version}</version>
+                </dependency>
 
                <dependency>
                        <groupId>com.att.eelf</groupId>
                        <artifactId>eelf-core</artifactId>
+                       <exclusions>
+                            <exclusion>
+                                 <groupId>ch.qos.logback</groupId>
+                                 <artifactId>logback-classic</artifactId>
+                            </exclusion>
+                        </exclusions>
                </dependency>
 
                <dependency>
index 1959093..3ce00be 100644 (file)
             <groupId>org.apache.commons</groupId>
             <artifactId>commons-lang3</artifactId>
         </dependency>
+        <dependency>
+         <groupId>ch.qos.logback</groupId>
+         <artifactId>logback-classic</artifactId>
+        <version>${logback.version}</version>
+        </dependency>
         <dependency>
             <groupId>com.att.eelf</groupId>
             <artifactId>eelf-core</artifactId>
+            <exclusions>
+                 <exclusion>
+                     <groupId>ch.qos.logback</groupId>
+                     <artifactId>logback-classic</artifactId>
+                 </exclusion>
+            </exclusions>
         </dependency>
         <dependency>
             <groupId>commons-configuration</groupId>
index f3cd09b..4a6da1f 100644 (file)
             <groupId>com.fasterxml.jackson.dataformat</groupId>
             <artifactId>jackson-dataformat-yaml</artifactId>
         </dependency>
+        <dependency>
+            <groupId>ch.qos.logback</groupId>
+            <artifactId>logback-classic</artifactId>
+           <version>${logback.version}</version>
+        </dependency>
         <dependency>
             <groupId>com.att.eelf</groupId>
             <artifactId>eelf-core</artifactId>
+            <exclusions>
+                <exclusion>
+                    <groupId>ch.qos.logback</groupId>
+                    <artifactId>logback-classic</artifactId>
+                </exclusion>
+            </exclusions>
         </dependency>
         <dependency>
             <groupId>org.onap.ccsdk.sli.adaptors</groupId>
index 0f72a16..07300f5 100644 (file)
   \r
   <dependencies>\r
     <!--  logging  -->\r
+    <dependency>\r
+         <groupId>ch.qos.logback</groupId>\r
+         <artifactId>logback-classic</artifactId>\r
+        <version>${logback.version}</version>\r
+    </dependency>\r
     <dependency>\r
       <groupId>com.att.eelf</groupId>\r
       <artifactId>eelf-core</artifactId>\r
+      <exclusions>\r
+           <exclusion>\r
+               <groupId>ch.qos.logback</groupId>\r
+               <artifactId>logback-classic</artifactId>\r
+           </exclusion>\r
+      </exclusions>\r
     </dependency>\r
     <dependency>\r
       <groupId>org.slf4j</groupId>\r
           </plugin>\r
     </plugins>  \r
   </build>\r
-</project>
\ No newline at end of file
+</project>\r
index 929d7cf..1cec77b 100644 (file)
                        <version>${project.version}</version>
                </dependency>
 -->
+                <dependency>
+                     <groupId>ch.qos.logback</groupId>
+                     <artifactId>logback-classic</artifactId>
+                    <version>${logback.version}</version>
+                </dependency>
                <dependency>
                        <groupId>com.att.eelf</groupId>
                        <artifactId>eelf-core</artifactId>
-                       </dependency>
+                       <exclusions>
+                            <exclusion>
+                                 <groupId>ch.qos.logback</groupId>
+                                 <artifactId>logback-classic</artifactId>
+                            </exclusion>
+                        </exclusions>
+               </dependency>
                <dependency>
                        <groupId>org.onap.appc</groupId>
                        <artifactId>appc-common</artifactId>
                <dependency>
                        <groupId>org.mockito</groupId>
                        <artifactId>mockito-core</artifactId>
+                       <scope>test</scope>
                </dependency>
        </dependencies>
 
index 7197c06..2adfd30 100755 (executable)
             <artifactId>sal-binding-broker-impl</artifactId>
             <scope>test</scope>
         </dependency>
-
+        <dependency>
+         <groupId>ch.qos.logback</groupId>
+         <artifactId>logback-classic</artifactId>
+        <version>${logback.version}</version>
+        </dependency>
         <dependency>
             <groupId>com.att.eelf</groupId>
             <artifactId>eelf-core</artifactId>
+            <exclusions>
+                 <exclusion>
+                      <groupId>ch.qos.logback</groupId>
+                      <artifactId>logback-classic</artifactId>
+                 </exclusion>
+            </exclusions>
         </dependency>
         <dependency>
             <groupId>org.onap.ccsdk.sli.adaptors</groupId>
index f9d21e1..403595f 100644 (file)
             <artifactId>sal-binding-broker-impl</artifactId>
             <scope>test</scope>
         </dependency>
-
+        <dependency>
+         <groupId>ch.qos.logback</groupId>
+         <artifactId>logback-classic</artifactId>
+        <version>${logback.version}</version>
+        </dependency>
         <dependency>
             <groupId>com.att.eelf</groupId>
             <artifactId>eelf-core</artifactId>
+            <exclusions>
+                   <exclusion>
+                        <groupId>ch.qos.logback</groupId>
+                        <artifactId>logback-classic</artifactId>
+                   </exclusion>
+            </exclusions>
         </dependency>
         <dependency>
             <groupId>com.sun.jersey</groupId>
index c762692..e9bf49a 100644 (file)
             <artifactId>state-machine-lib</artifactId>
             <version>${project.version}</version>
         </dependency>
+        <dependency>
+         <groupId>ch.qos.logback</groupId>
+         <artifactId>logback-classic</artifactId>
+        <version>${logback.version}</version>
+        </dependency>
         <dependency>
             <groupId>com.att.eelf</groupId>
             <artifactId>eelf-core</artifactId>
+            <exclusions>
+                  <exclusion>
+                       <groupId>ch.qos.logback</groupId>
+                       <artifactId>logback-classic</artifactId>
+                  </exclusion>
+            </exclusions>
         </dependency>
     </dependencies>
 
index 836e298..16645dc 100755 (executable)
                        <artifactId>commons-io</artifactId>\r
                        <version>2.5</version>\r
                </dependency>\r
-        <dependency>\r
+                <dependency>\r
                        <groupId>org.apache.commons</groupId>\r
                        <artifactId>commons-lang3</artifactId>\r
                </dependency>\r
-\r
+                <dependency>\r
+                        <groupId>ch.qos.logback</groupId>\r
+                        <artifactId>logback-classic</artifactId>\r
+                       <version>${logback.version}</version>\r
+                </dependency>\r
                <dependency>\r
                        <groupId>com.att.eelf</groupId>\r
                        <artifactId>eelf-core</artifactId>\r
+                        <exclusions>\r
+                            <exclusion>\r
+                                 <groupId>ch.qos.logback</groupId>\r
+                                 <artifactId>logback-classic</artifactId>\r
+                            </exclusion>\r
+                        </exclusions>\r
                </dependency>\r
 \r
                <dependency>\r
index e2edfba..b91cbe6 100755 (executable)
             <groupId>commons-io</groupId>\r
             <artifactId>commons-io</artifactId>\r
         </dependency>\r
+        <dependency>\r
+         <groupId>ch.qos.logback</groupId>\r
+         <artifactId>logback-classic</artifactId>\r
+        <version>${logback.version}</version>\r
+        </dependency>\r
         <dependency>\r
             <groupId>com.att.eelf</groupId>\r
             <artifactId>eelf-core</artifactId>\r
+            <exclusions>\r
+                 <exclusion>\r
+                      <groupId>ch.qos.logback</groupId>\r
+                      <artifactId>logback-classic</artifactId>\r
+                 </exclusion>\r
+            </exclusions>\r
         </dependency>\r
         <dependency>\r
             <groupId>com.sun.jersey</groupId>\r
diff --git a/pom.xml b/pom.xml
index ee2185d..74b0b4b 100644 (file)
--- a/pom.xml
+++ b/pom.xml
@@ -377,7 +377,7 @@ limitations under the License.
             <dependency>
                 <groupId>ch.qos.logback</groupId>
                 <artifactId>logback-core</artifactId>
-                               <version>${logback.version}</version>
+               <version>${logback.version}</version>
                 <scope>compile</scope>
             </dependency>
             <dependency>