Update dependencies to latest 34/86534/4
authorMatthieu Geerebaert <matthieu.geerebaert@orange.com>
Mon, 29 Apr 2019 14:36:28 +0000 (16:36 +0200)
committerMatthieu Geerebaert <matthieu.geerebaert@orange.com>
Mon, 29 Apr 2019 14:42:27 +0000 (16:42 +0200)
Resolve some vulnerabilities issues

Change-Id: I26d4a6cab86a5ddb25700c7b437051ea1aa49f81
Issue-ID: EXTAPI-236
Signed-off-by: MatthieuGeerebaert <matthieu.geerebaert@orange.com>
.gitignore
pom.xml

index 8cb38f5..96b743f 100644 (file)
 ### Linux related ###
 *~
 
+### Restructured Text ###
+conf.py
+__*
+_static
+
 # KDE directory preferences
 .directory
 
diff --git a/pom.xml b/pom.xml
index f8d8c9a..164d2ca 100644 (file)
--- a/pom.xml
+++ b/pom.xml
       <dependency>
         <groupId>org.springframework.boot</groupId>
         <artifactId>spring-boot-dependencies</artifactId>
-        <version>2.1.3.RELEASE</version>
+        <version>2.1.4.RELEASE</version>
         <type>pom</type>
         <scope>import</scope>
       </dependency>
     <dependency>
       <groupId>org.springframework.boot</groupId>
       <artifactId>spring-boot-starter-web</artifactId>
+      <exclusions>
+        <exclusion>
+          <groupId>org.apache.tomcat.embed</groupId>
+          <artifactId>tomcat-embed-core</artifactId>
+        </exclusion>
+      </exclusions>
+    </dependency>
+
+    <dependency>
+      <groupId>org.apache.tomcat.embed</groupId>
+      <artifactId>tomcat-embed-core</artifactId>
+      <version>9.0.19</version>
     </dependency>
 
     <dependency>
           <groupId>com.google.guava</groupId>
           <artifactId>guava</artifactId>
         </exclusion>
+        <exclusion>
+          <groupId>commons-codec</groupId>
+          <artifactId>commons-codec</artifactId>
+        </exclusion>
       </exclusions>
     </dependency>
 
+    <dependency>
+      <groupId>commons-codec</groupId>
+      <artifactId>commons-codec</artifactId>
+      <version>1.12</version>
+    </dependency>
+
     <!-- jolt -->
 
     <dependency>
           <groupId>com.fasterxml.jackson.core</groupId>
           <artifactId>jackson-databind</artifactId>
         </exclusion>
+        <exclusion>
+          <groupId>commons-codec</groupId>
+          <artifactId>commons-codec</artifactId>
+        </exclusion>
       </exclusions>
     </dependency>
 
           <groupId>com.google.guava</groupId>
           <artifactId>guava</artifactId>
         </exclusion>
+        <exclusion>
+          <groupId>com.squareup.okhttp3</groupId>
+          <artifactId>okhttp</artifactId>
+        </exclusion>
       </exclusions>
     </dependency>
 
+    <dependency>
+      <groupId>com.squareup.okhttp3</groupId>
+      <artifactId>okhttp</artifactId>
+      <version>3.14.1</version>
+    </dependency>
+
     <dependency>
       <groupId>com.google.guava</groupId>
       <artifactId>guava</artifactId>