reduce CDS java security vulnerabilities
[ccsdk/parent.git] / dependencies-bom / pom.xml
index 67c1936..4ab72d1 100644 (file)
@@ -4,7 +4,7 @@
 
     <groupId>org.onap.ccsdk.parent</groupId>
     <artifactId>dependencies-bom</artifactId>
-    <version>2.4.2-SNAPSHOT</version>
+    <version>2.7.0-SNAPSHOT</version>
     <packaging>pom</packaging>
 
     <distributionManagement>
             <dependency>
                 <groupId>com.fasterxml.jackson</groupId>
                 <artifactId>jackson-bom</artifactId>
-                <!-- ODL Aluminum has 2.10.5 -->
-                <version>2.12.4</version>
+                <version>2.14.1</version>
                 <type>pom</type>
                 <scope>import</scope>
             </dependency>
             <dependency>
                 <groupId>com.google.code.gson</groupId>
                 <artifactId>gson</artifactId>
-                <version>2.8.9</version>
+                <version>2.9.0</version>
             </dependency>
             <dependency>
                 <groupId>com.google.guava</groupId>
             <dependency>
                 <groupId>io.grpc</groupId>
                 <artifactId>grpc-bom</artifactId>
-                <version>1.25.0</version>
+                <version>1.29.0</version>
                 <type>pom</type>
                 <scope>import</scope>
             </dependency>
             <dependency>
                 <groupId>org.antlr</groupId>
                 <artifactId>antlr4-runtime</artifactId>
-                <version>4.8-1</version>
+                <version>4.12.0</version>
             </dependency>
             <dependency>
                 <groupId>org.apache.commons</groupId>
             <dependency>
                 <groupId>org.apache.logging.log4j</groupId>
                 <artifactId>log4j-slf4j-impl</artifactId>
-                <version>2.17.1</version>
+                <version>2.17.2</version>
             </dependency>
             <dependency>
                 <groupId>org.apache.logging.log4j</groupId>
                 <artifactId>log4j-core</artifactId>
-                <version>2.17.1</version>
+                <version>2.17.2</version>
             </dependency>
             <dependency>
                 <groupId>org.apache.tomcat</groupId>