|
22 | 22 | <parent> |
23 | 23 | <groupId>org.commonjava</groupId> |
24 | 24 | <artifactId>commonjava</artifactId> |
25 | | - <version>18</version> |
| 25 | + <version>21</version> |
26 | 26 | </parent> |
27 | 27 |
|
28 | 28 | <groupId>org.commonjava.util</groupId> |
|
53 | 53 | <javaVersion>11</javaVersion> |
54 | 54 | <test-forkCount>1</test-forkCount> |
55 | 55 | <metricsVersion>4.2.21</metricsVersion> |
56 | | - <otelVersion>1.19.0</otelVersion> |
| 56 | + <otelVersion>1.32.0</otelVersion> |
57 | 57 | <prometheusVersion>0.16.0</prometheusVersion> |
58 | | - <logbackVersion>1.2.12</logbackVersion> |
59 | | - <undertowVersion>2.2.28.Final</undertowVersion> |
| 58 | + <undertowVersion>2.2.38.Final</undertowVersion> |
60 | 59 | <agroalVersion>1.16</agroalVersion> |
61 | | - <datastaxVersion>3.11.5</datastaxVersion> |
62 | | - <httpclientVersion>4.5.13</httpclientVersion> |
63 | | - <jhttpcVersion>1.12</jhttpcVersion> |
| 60 | + <cassandraVersion>3.12.1</cassandraVersion> |
| 61 | + <jhttpcVersion>1.16</jhttpcVersion> |
64 | 62 | </properties> |
65 | 63 |
|
66 | 64 | <dependencyManagement> |
67 | 65 | <dependencies> |
| 66 | + <!-- Managing vulnerable versions of netty from cassandra to avoid CVE --> |
| 67 | + <dependency> |
| 68 | + <groupId>io.netty</groupId> |
| 69 | + <artifactId>netty-handler</artifactId> |
| 70 | + <version>4.1.118.Final</version> |
| 71 | + </dependency> |
| 72 | + |
68 | 73 | <dependency> |
69 | 74 | <groupId>org.commonjava.boms</groupId> |
70 | 75 | <artifactId>web-commons-bom</artifactId> |
71 | | - <version>29</version> |
| 76 | + <version>31</version> |
72 | 77 | <type>pom</type> |
73 | 78 | <scope>import</scope> |
74 | 79 | </dependency> |
|
185 | 190 | <version>${prometheusVersion}</version> |
186 | 191 | </dependency> |
187 | 192 |
|
188 | | - <dependency> |
189 | | - <groupId>ch.qos.logback</groupId> |
190 | | - <artifactId>logback-classic</artifactId> |
191 | | - <version>${logbackVersion}</version> |
192 | | - </dependency> |
193 | | - <dependency> |
194 | | - <groupId>ch.qos.logback</groupId> |
195 | | - <artifactId>logback-core</artifactId> |
196 | | - <version>${logbackVersion}</version> |
197 | | - </dependency> |
198 | | - |
199 | 193 | <dependency> |
200 | 194 | <groupId>org.commonjava.util</groupId> |
201 | 195 | <artifactId>jhttpc</artifactId> |
|
209 | 203 | </dependency> |
210 | 204 |
|
211 | 205 | <dependency> |
212 | | - <groupId>com.datastax.cassandra</groupId> |
213 | | - <artifactId>cassandra-driver-core</artifactId> |
214 | | - <version>${datastaxVersion}</version> |
| 206 | + <groupId>io.netty</groupId> |
| 207 | + <artifactId>netty-handler</artifactId> |
215 | 208 | </dependency> |
216 | | - |
217 | 209 | <dependency> |
218 | | - <groupId>org.apache.httpcomponents</groupId> |
219 | | - <artifactId>httpclient</artifactId> |
220 | | - <version>${httpclientVersion}</version> |
| 210 | + <groupId>org.apache.cassandra</groupId> |
| 211 | + <artifactId>cassandra-driver-core</artifactId> |
| 212 | + <version>${cassandraVersion}</version> |
| 213 | + <exclusions> |
| 214 | + <exclusion> |
| 215 | + <groupId>io.netty</groupId> |
| 216 | + <artifactId>netty-handler</artifactId> |
| 217 | + </exclusion> |
| 218 | + </exclusions> |
221 | 219 | </dependency> |
222 | 220 |
|
223 | 221 | <dependency> |
|
263 | 261 | <groupId>commons-io</groupId> |
264 | 262 | <artifactId>commons-io</artifactId> |
265 | 263 | </dependency> |
266 | | - <dependency> |
267 | | - <groupId>commons-lang</groupId> |
268 | | - <artifactId>commons-lang</artifactId> |
269 | | - </dependency> |
270 | 264 | <dependency> |
271 | 265 | <groupId>org.apache.commons</groupId> |
272 | 266 | <artifactId>commons-lang3</artifactId> |
273 | | - <version>3.12.0</version> |
274 | 267 | </dependency> |
275 | 268 | <dependency> |
276 | 269 | <groupId>commons-codec</groupId> |
|
0 commit comments