Add spring dependencies into dependency management 69/128769/1
authorliamfallon <liam.fallon@est.tech>
Thu, 21 Apr 2022 11:52:54 +0000 (12:52 +0100)
committerliamfallon <liam.fallon@est.tech>
Thu, 21 Apr 2022 11:55:10 +0000 (12:55 +0100)
Some dependencies were missing in oparent and then did not respect the
spring.version parameter for setting the spring version, dragging in the
vulnerable version of spring-beans.

Issue-ID: POLICY-4070
Change-Id: I819062a6165bbec33498414c4f4401cb41475028
Signed-off-by: liamfallon <liam.fallon@est.tech>
.gitignore
dependencies/pom.xml

index 32edeae..d7497b4 100644 (file)
@@ -3,4 +3,5 @@ target
 .project
 .settings
 .classpath
+**/*.iml
 cia/
index f75a7c5..33b10e0 100644 (file)
         <artifactId>spring-core</artifactId>
         <version>${spring.version}</version>
       </dependency>
+      <dependency>
+        <groupId>org.springframework</groupId>
+        <artifactId>spring-beans</artifactId>
+        <version>${spring.version}</version>
+      </dependency>
       <dependency>
         <groupId>org.springframework</groupId>
         <artifactId>spring-expression</artifactId>
         <artifactId>spring-webmvc</artifactId>
         <version>${spring.version}</version>
       </dependency>
+      <dependency>
+        <groupId>org.springframework</groupId>
+        <artifactId>spring-jdbc</artifactId>
+        <version>${spring.version}</version>
+      </dependency>
+      <dependency>
+        <groupId>org.springframework</groupId>
+        <artifactId>spring-webflux</artifactId>
+        <version>${spring.version}</version>
+      </dependency>
       <dependency>
         <groupId>commons-beanutils</groupId>
         <artifactId>commons-beanutils</artifactId>