[DMAAP-MR] Update kohn sec vul packages 73/130873/2 1.4.1
authorefiacor <fiachra.corcoran@est.tech>
Tue, 13 Sep 2022 13:18:09 +0000 (14:18 +0100)
committerefiacor <fiachra.corcoran@est.tech>
Tue, 13 Sep 2022 14:02:35 +0000 (15:02 +0100)
Signed-off-by: efiacor <fiachra.corcoran@est.tech>
Change-Id: I8aa8af342ba359e00b342628d9ea1ee0c8444c49
Issue-ID: DMAAP-1748

pom.xml
src/main/config/ajsc-jetty.xml

diff --git a/pom.xml b/pom.xml
index 91b5fee..4574bc5 100644 (file)
--- a/pom.xml
+++ b/pom.xml
                <onap.nexus.url>https://nexus.onap.org</onap.nexus.url>
                <maven.build.timestamp.format>yyyyMMdd'T'HHmmss'Z'</maven.build.timestamp.format>
                <camel.version>2.21.5</camel.version>
-               <camel.version.latest>3.5.0</camel.version.latest>
+               <camel.version.latest>3.17.0</camel.version.latest>
                <skip.docker.build>false</skip.docker.build>
                <skip.docker.tag>false</skip.docker.tag>
                <skip.docker.push>false</skip.docker.push>
                <docker.push.registry>nexus3.onap.org:10003</docker.push.registry>
                <nexusproxy>https://nexus.onap.org</nexusproxy>
-               <spring.version>3.2.18.RELEASE</spring.version>
+               <spring.version>5.3.20</spring.version>
                <sonar.language>java</sonar.language>
                <sonar.skip>false</sonar.skip>
                <sonar.surefire.reportsPath>${project.build.directory}/surefire-reports</sonar.surefire.reportsPath>
                <dependency>
                        <groupId>com.fasterxml.woodstox</groupId>
                        <artifactId>woodstox-core</artifactId>
-                       <version>5.3.0</version>
+                       <version>6.2.8</version>
                </dependency>
                <dependency>
                        <groupId>org.grails</groupId>
                <dependency>
                        <groupId>org.springframework</groupId>
                        <artifactId>spring-context</artifactId>
-                       <version>4.3.18.RELEASE</version>
+                       <version>${spring.version}</version>
                </dependency>
                <dependency>
                        <groupId>org.springframework</groupId>
                        <artifactId>spring-webmvc</artifactId>
-                       <version>5.3.3</version>
+                       <version>${spring.version}</version>
                </dependency>
                <dependency>
                        <groupId>org.springframework</groupId>
                        <artifactId>spring-core</artifactId>
-                       <version>4.3.18.RELEASE</version>
+                       <version>${spring.version}</version>
                </dependency>
                <dependency>
                        <groupId>org.springframework</groupId>
                        <artifactId>spring-beans</artifactId>
-                       <version>4.3.18.RELEASE</version>
+                       <version>${spring.version}</version>
                </dependency>
                <dependency>
                        <groupId>commons-io</groupId>
                <dependency>
                        <groupId>com.fasterxml.jackson.core</groupId>
                        <artifactId>jackson-databind</artifactId>
+                       <version>2.13.4</version>
                </dependency>
                <dependency>
                        <groupId>org.grails</groupId>
                <dependency>
                        <groupId>org.json</groupId>
                        <artifactId>json</artifactId>
-                       <version>20131018</version>
+                       <version>20220320</version>
                </dependency>
                <!-- CXF JAX-RS extension -->
                <dependency>
                        <artifactId>ajsc-runner</artifactId>
                        <version>3.0.11-oss</version>
                        <scope>runtime</scope>
+                       <exclusions>
+                               <exclusion>
+                                       <groupId>org.json</groupId>
+                                       <artifactId>json</artifactId>
+                               </exclusion>
+                               <exclusion>
+                                       <groupId>org.eclipse.jetty</groupId>
+                                       <artifactId>jetty-util</artifactId>
+                               </exclusion>
+                               <exclusion>
+                                       <groupId>org.quartz-scheduler</groupId>
+                                       <artifactId>quartz</artifactId>
+                               </exclusion>
+                       </exclusions>
                </dependency>
                <dependency>
                        <groupId>com.att.ajsc</groupId>
index 449f7de..6b519d2 100644 (file)
@@ -32,7 +32,7 @@
                <Set name="descriptor"><SystemProperty name="AJSC_HOME" />/etc/runner-web.xml</Set>
                <Set name="overrideDescriptor"><SystemProperty name="AJSC_HOME" />/etc/ajsc-override-web.xml</Set>
                <Set name="throwUnavailableOnStartupException">true</Set>
-               <Set name="extraClasspath"><SystemProperty name="AJSC_HOME" />/extJars/json-20131018.jar</Set>
+               <Set name="extraClasspath"><SystemProperty name="AJSC_HOME" />/extJars/json-20220320.jar</Set>
                <Set name="servletHandler">
                        <New class="org.eclipse.jetty.servlet.ServletHandler">
                                <Set name="startWithUnavailable">false</Set>