Fix security issue in java 03/55703/1
authorDeterme, Sebastien (sd378r) <sd378r@intl.att.com>
Tue, 3 Jul 2018 13:38:34 +0000 (15:38 +0200)
committerDeterme, Sebastien (sd378r) <sd378r@intl.att.com>
Tue, 3 Jul 2018 13:38:34 +0000 (15:38 +0200)
Remove/upgrade some java libs reported by Nexus IQ

Issue-ID: CLAMP-192
Change-Id: If39dc00abfad081c9298c663c99b747a90693fc0
Signed-off-by: Determe, Sebastien (sd378r) <sd378r@intl.att.com>
pom.xml

diff --git a/pom.xml b/pom.xml
index b2a397f..5a9fad7 100644 (file)
--- a/pom.xml
+++ b/pom.xml
@@ -68,7 +68,6 @@
                                <java.version>1.8</java.version>
 
                                <swagger.jaxrs2.version>2.0.0-rc4</swagger.jaxrs2.version>
-                               <guava.version>20.0</guava.version>
                                <eelf.core.version>1.0.0</eelf.core.version>
                                <camel.version>2.20.1</camel.version>
                                <springboot.version>1.5.14.RELEASE</springboot.version>
                                                <artifactId>commons-csv</artifactId>
                                                <version>1.3</version>
                                </dependency>
-                               <dependency>
-                                               <groupId>com.sun.faces</groupId>
-                                               <artifactId>jsf-api</artifactId>
-                                               <version>2.1.7</version>
-                               </dependency>
-                               <dependency>
-                                               <groupId>com.sun.faces</groupId>
-                                               <artifactId>jsf-impl</artifactId>
-                                               <version>2.1.7</version>
-                               </dependency>
                                <!-- Other dependencies to fix nexus IQ reported vulnerabilities -->
                                <dependency>
                                                <groupId>org.codehaus.plexus</groupId>
                                                <artifactId>jboss-jaxrs-api_2.0_spec</artifactId>
                                                <version>1.0.1.Final</version>
                                </dependency>
+                               <dependency>
+                                               <groupId>com.google.guava</groupId>
+                                               <artifactId>guava</artifactId>
+                                               <version>25.1-jre</version>
+                               </dependency>
                                <!-- Remove the MYSQL connector and replace it by Mariadb -->
                                <dependency>
                                                <groupId>org.mariadb.jdbc</groupId>