Update vulnerable dependencies 70/129770/5
authorvasraz <vasyl.razinkov@est.tech>
Sat, 2 Jul 2022 23:54:33 +0000 (00:54 +0100)
committerAndr� Schmid <andre.schmid@est.tech>
Tue, 5 Jul 2022 14:49:55 +0000 (14:49 +0000)
Signed-off-by: Vasyl Razinkov <vasyl.razinkov@est.tech>
Change-Id: I24d9a59b483057187a57d2e43d82accebbf8fc57
Issue-ID: SDC-4017

catalog-be/pom.xml
common-app-api/pom.xml
common-be-tests-utils/pom.xml
common-be/pom.xml
pom.xml

index 1187392..58c2f24 100644 (file)
                     <groupId>org.hibernate</groupId>
                     <artifactId>hibernate-validator</artifactId>
                 </exclusion>
+                <exclusion>
+                    <groupId>org.glassfish</groupId>
+                    <artifactId>jakarta.el</artifactId>
+                </exclusion>
             </exclusions>
         </dependency>
+        <dependency>
+            <groupId>org.glassfish</groupId>
+            <artifactId>jakarta.el</artifactId>
+            <version>${jakarta.el.version}</version>
+        </dependency>
 
         <!-- http client -->
         <dependency>
index d51fb57..7905404 100644 (file)
       <groupId>org.springframework.boot</groupId>
       <artifactId>spring-boot-starter</artifactId>
       <version>${spring.boot.version}</version>
+      <exclusions>
+        <exclusion>
+          <groupId>org.yaml</groupId>
+          <artifactId>snakeyaml</artifactId>
+        </exclusion>
+      </exclusions>
     </dependency>
     <dependency>
       <groupId>org.onap.sdc.sdc-be-common</groupId>
           <groupId>org.onap.portal.sdk</groupId>
           <artifactId>epsdk-fw</artifactId>
         </exclusion>
+        <exclusion>
+          <groupId>org.glassfish</groupId>
+          <artifactId>jakarta.el</artifactId>
+        </exclusion>
       </exclusions>
     </dependency>
+    <dependency>
+      <groupId>org.glassfish</groupId>
+      <artifactId>jakarta.el</artifactId>
+      <version>${jakarta.el.version}</version>
+    </dependency>
+
     <dependency>
       <groupId>commons-io</groupId>
       <artifactId>commons-io</artifactId>
index 4d0cfb4..b2b04be 100644 (file)
         <dependency>
             <groupId>io.minio</groupId>
             <artifactId>minio</artifactId>
-            <version>8.3.4</version>
+            <version>${minio.version}</version>
+            <exclusions>
+                <exclusion>
+                    <groupId>com.squareup.okhttp3</groupId>
+                    <artifactId>okhttp</artifactId>
+                </exclusion>
+            </exclusions>
+        </dependency>
+        <dependency>
+            <groupId>com.squareup.okhttp3</groupId>
+            <artifactId>okhttp</artifactId>
+            <version>${okhttp.version}</version>
         </dependency>
 
         <!-- Common of SD&C -->
index 3f8a975..02a3a3a 100644 (file)
         <dependency>
             <groupId>io.minio</groupId>
             <artifactId>minio</artifactId>
-            <version>8.3.4</version>
+            <version>${minio.version}</version>
+            <exclusions>
+                <exclusion>
+                    <groupId>com.squareup.okhttp3</groupId>
+                    <artifactId>okhttp</artifactId>
+                </exclusion>
+            </exclusions>
+        </dependency>
+        <dependency>
+            <groupId>com.squareup.okhttp3</groupId>
+            <artifactId>okhttp</artifactId>
+            <version>${okhttp.version}</version>
         </dependency>
 
         <!-- Common of SD&C -->
diff --git a/pom.xml b/pom.xml
index 7e2165d..fcd64ae 100644 (file)
--- a/pom.xml
+++ b/pom.xml
@@ -49,7 +49,12 @@ Modifications copyright (c) 2018-2019 Nokia
         <janusgraph.version>0.3.3</janusgraph.version>
         <spring.version>5.3.18</spring.version>
         <spring.boot.version>2.2.13.RELEASE</spring.boot.version>
+
+        <!-- update to 2.36 bring error-->
+        <!-- java.lang.NoClassDefFoundError: com/fasterxml/jackson/databind/AnnotationIntrospector$XmlExtensions-->
         <jersey-bom.version>2.34</jersey-bom.version>
+        <jakarta.el.version>3.0.4</jakarta.el.version>
+
         <netty.version>4.1.77.Final</netty.version>
         <servlet-api.version>4.0.1</servlet-api.version>
         <wire-mock.version>2.26.3</wire-mock.version>
@@ -192,6 +197,9 @@ Modifications copyright (c) 2018-2019 Nokia
 
         <micrometer.version>1.8.4</micrometer.version>
 
+        <minio.version>8.3.4</minio.version>
+        <okhttp.version>4.9.3</okhttp.version>
+
         <verbose>false</verbose>
     </properties>