Update vulnerable dependencies 81/134581/10
authorvasraz <vasyl.razinkov@est.tech>
Thu, 18 May 2023 15:13:52 +0000 (16:13 +0100)
committerMichael Morris <michael.morris@est.tech>
Thu, 25 May 2023 12:09:03 +0000 (12:09 +0000)
Signed-off-by: Vasyl Razinkov <vasyl.razinkov@est.tech>
Change-Id: Ifedc08763f6d46e3bcba0367a81edc8e219865d0
Issue-ID: SDC-4504

asdctool/pom.xml
catalog-be/pom.xml
catalog-dao/pom.xml
catalog-model/pom.xml
catalog-model/src/main/java/org/openecomp/sdc/be/model/User.java
onboarding/pom.xml
openecomp-be/tools/swagger-ui/pom.xml
openecomp-be/tools/zusammen-tools/pom.xml
pom.xml

index 4dba42e..6431e31 100644 (file)
     <version>1.12.4-SNAPSHOT</version>
   </parent>
 
+  <properties>
+    <apache-poi.version>5.2.3</apache-poi.version>
+  </properties>
+
   <dependencies>
     <dependency>
       <groupId>com.google.guava</groupId>
       <scope>compile</scope>
     </dependency>
 
-    <!-- slf4j + logback -->
-    <dependency>
-      <groupId>org.slf4j</groupId>
-      <artifactId>slf4j-api</artifactId>
-      <version>${slf4j-api.version}</version>
-      <scope>compile</scope>
-    </dependency>
-
+    <!-- logback -->
     <dependency>
       <groupId>ch.qos.logback</groupId>
       <artifactId>logback-classic</artifactId>
       <version>${janusgraph.version}</version>
       <scope>compile</scope>
       <exclusions>
+        <exclusion>
+          <groupId>joda-time</groupId>
+          <artifactId>joda-time</artifactId>
+        </exclusion>
         <exclusion>
           <groupId>org.slf4j</groupId>
           <artifactId>slf4j-log4j12</artifactId>
       <plugin>
         <groupId>org.apache.maven.plugins</groupId>
         <artifactId>maven-assembly-plugin</artifactId>
+        <version>${mvn.assembly.version}</version>
         <executions>
           <execution>
             <configuration>
index 987b2e7..cea9a32 100644 (file)
             <version>${jsoup.version}</version>
         </dependency>
 
-        <dependency>
-            <groupId>org.slf4j</groupId>
-            <artifactId>slf4j-api</artifactId>
-            <version>${slf4j-api.version}</version>
-        </dependency>
-
         <!--JSON and YAML Parsing-->
         <dependency>
             <groupId>com.fasterxml.jackson.core</groupId>
             <plugin>
                 <groupId>org.apache.maven.plugins</groupId>
                 <artifactId>maven-assembly-plugin</artifactId>
+                <version>${mvn.assembly.version}</version>
                 <executions>
                     <execution>
                         <id>normatives</id>
index 279aa3a..a4474d0 100644 (file)
@@ -373,6 +373,10 @@ Modifications copyright (c) 2018 Nokia
       <version>${janusgraph.version}</version>
       <scope>provided</scope>
       <exclusions>
+        <exclusion>
+          <groupId>joda-time</groupId>
+          <artifactId>joda-time</artifactId>
+        </exclusion>
         <exclusion>
           <groupId>org.slf4j</groupId>
           <artifactId>slf4j-log4j12</artifactId>
@@ -482,6 +486,10 @@ Modifications copyright (c) 2018 Nokia
       <artifactId>cassandra-all</artifactId>
       <version>${cassandra-all.version}</version>
       <exclusions>
+        <exclusion>
+          <groupId>joda-time</groupId>
+          <artifactId>joda-time</artifactId>
+        </exclusion>
         <exclusion>
           <groupId>org.apache.thrift</groupId>
           <artifactId>libthrift</artifactId>
index eb09dc1..2577bf0 100644 (file)
             <version>${janusgraph.version}</version>
             <scope>provided</scope>
             <exclusions>
+                <exclusion>
+                    <groupId>joda-time</groupId>
+                    <artifactId>joda-time</artifactId>
+                </exclusion>
                 <exclusion>
                     <artifactId>slf4j-log4j12</artifactId>
                     <groupId>org.slf4j</groupId>
             <artifactId>lombok</artifactId>
             <version>${lombok.version}</version>
         </dependency>
-        <dependency>
-            <groupId>joda-time</groupId>
-            <artifactId>joda-time</artifactId>
-            <version>${joda.time.version}</version>
-        </dependency>
         <dependency>
             <groupId>org.openecomp.sdc.core</groupId>
             <artifactId>openecomp-tosca-lib</artifactId>
index 72dc4aa..0d44cff 100644 (file)
 package org.openecomp.sdc.be.model;
 
 import com.fasterxml.jackson.annotation.JsonInclude;
+import java.time.ZonedDateTime;
 import lombok.EqualsAndHashCode;
 import lombok.Getter;
 import lombok.NoArgsConstructor;
 import lombok.Setter;
 import lombok.ToString;
-import org.joda.time.DateTime;
-import org.joda.time.DateTimeZone;
 import org.openecomp.sdc.be.dao.utils.UserStatusEnum;
 import org.openecomp.sdc.common.util.NoHtml;
 
@@ -88,8 +87,7 @@ public class User {
     }
 
     public void setLastLoginTime() {
-        DateTime now = new DateTime(DateTimeZone.UTC);
-        this.lastLoginTime = now.getMillis();
+        this.lastLoginTime = ZonedDateTime.now().toInstant().toEpochMilli();
     }
 
 }
index 44c4b16..04e7dc3 100644 (file)
@@ -41,7 +41,6 @@
         <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
 
         <!-- Maven plugin versions -->
-        <mvn.assembly.version>2.1</mvn.assembly.version>
         <mvn.clean.version>2.5</mvn.clean.version>
         <mvn.resource.version>3.1.0</mvn.resource.version>
         <mvn.deploy.version>2.4</mvn.deploy.version>
index 9f69310..c136ef0 100644 (file)
             <plugin>
                 <groupId>org.apache.maven.plugins</groupId>
                 <artifactId>maven-assembly-plugin</artifactId>
-                <version>${mvn.assembly.version}</version>
+                <version>2.6</version>
                 <configuration>
                     <descriptor>assembly/swagger.xml</descriptor>
                     <finalName>${plugin.name}</finalName>
index b31472c..19777ce 100644 (file)
                 </executions>
             </plugin>
             <plugin>
+                <groupId>org.apache.maven.plugins</groupId>
                 <artifactId>maven-assembly-plugin</artifactId>
+                <version>${mvn.assembly.version}</version>
                 <executions>
                     <execution>
                         <id>Generate assembly</id>
diff --git a/pom.xml b/pom.xml
index 7844a52..1c2077f 100644 (file)
--- a/pom.xml
+++ b/pom.xml
@@ -48,14 +48,15 @@ Modifications copyright (c) 2018-2019 Nokia
         <guava.version>30.1-jre</guava.version>
         <janusgraph.version>0.3.3</janusgraph.version>
         <spring.version>5.3.26</spring.version>
-        <spring.boot.version>2.2.13.RELEASE</spring.boot.version>
+        <spring.boot.version>2.3.12.RELEASE</spring.boot.version>
+        <mvn.assembly.version>3.6.0</mvn.assembly.version>
 
         <!-- update to 2.36 bring error-->
         <!-- java.lang.NoClassDefFoundError: com/fasterxml/jackson/databind/AnnotationIntrospector$XmlExtensions-->
         <jersey-bom.version>2.34</jersey-bom.version>
         <jakarta.el.version>3.0.4</jakarta.el.version>
 
-        <netty.version>4.1.77.Final</netty.version>
+        <netty.version>4.1.92.Final</netty.version>
         <servlet-api.version>4.0.4</servlet-api.version>
         <wire-mock.version>2.26.3</wire-mock.version>
         <ecomp.version>3.4.0</ecomp.version>
@@ -64,7 +65,6 @@ Modifications copyright (c) 2018-2019 Nokia
         <commons-beanutils>1.9.4</commons-beanutils>
         <commons.io.version>2.8.0</commons.io.version>
         <commons-configuration>2.8.0</commons-configuration>
-        <apache-poi.version>4.1.0</apache-poi.version>
         <onap.logging.version>1.6.1</onap.logging.version>
         <apache-commons-text.version>1.10.0</apache-commons-text.version>
         <jaxb-api.version>2.3.1</jaxb-api.version>
@@ -173,8 +173,6 @@ Modifications copyright (c) 2018-2019 Nokia
         <!--togglz version-->
         <togglz.version>3.3.3</togglz.version>
 
-        <joda.time.version>2.9.9</joda.time.version>
-
         <!--sdc-security-utils-->
         <security.util.lib.version>1.8.0</security.util.lib.version>
         <!--jacoco-->
@@ -458,7 +456,7 @@ Modifications copyright (c) 2018-2019 Nokia
                 <plugin>
                     <groupId>org.apache.maven.plugins</groupId>
                     <artifactId>maven-assembly-plugin</artifactId>
-                    <version>3.1.0</version>
+                    <version>${mvn.assembly.version}</version>
                     <configuration>
                         <tarLongFileMode>posix</tarLongFileMode>
                     </configuration>