Skip to content
This repository was archived by the owner on Feb 27, 2025. It is now read-only.

Commit da3362a

Browse files
Resolving vulnerablities by upgrading versions and excluding dependencies
Excluding dependencies vulnerablities of spring-core, spring-security core, Bump up versions of netty, log4j, plexus
1 parent 1c53d5e commit da3362a

File tree

1 file changed

+32
-2
lines changed

1 file changed

+32
-2
lines changed

pom.xml

Lines changed: 32 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,7 @@
4949
<spring.boot.version>2.2.13.RELEASE</spring.boot.version>
5050
<spring.cloud.version>2.0.2.RELEASE</spring.cloud.version>
5151
<springframework.version>5.1.20.RELEASE</springframework.version>
52+
<kotlin-stdlib.version>1.6.0</kotlin-stdlib.version>
5253
<springframework-plugin.version>1.2.0.RELEASE</springframework-plugin.version>
5354
<swagger-version>2.9.2</swagger-version>
5455
<spring.hateoas.version>0.25.1.RELEASE</spring.hateoas.version>
@@ -94,10 +95,10 @@
9495
<hazelcast-kubernetes.version>1.3.1</hazelcast-kubernetes.version>
9596
<org.json.version>20180130</org.json.version>
9697
<net.jpountz.lz4.version>1.3.0</net.jpountz.lz4.version>
97-
<log4j.version>2.17.0</log4j.version>
98+
<log4j.version>2.17.1</log4j.version>
9899
<avro-version>1.10.2</avro-version>
99100
<asynchttpclient.version>2.12.3</asynchttpclient.version>
100-
<netty.version>4.1.68.Final</netty.version>
101+
<netty.version>4.1.86.Final</netty.version>
101102
<tomcat.version>9.0.54</tomcat.version>
102103
<netty-reactive-streams-version>2.0.5</netty-reactive-streams-version>
103104
<aws-sdk.version>1.11.579</aws-sdk.version>
@@ -136,6 +137,12 @@
136137
<groupId>org.springframework</groupId>
137138
<artifactId>spring-core</artifactId>
138139
<version>${springframework.version}</version>
140+
<exclusions>
141+
<exclusion>
142+
<groupId>org.jetbrains.kotlin</groupId>
143+
<artifactId>kotlin-stdlib</artifactId>
144+
</exclusion>
145+
</exclusions>
139146
</dependency>
140147
<dependency>
141148
<groupId>org.springframework</groupId>
@@ -147,6 +154,11 @@
147154
<artifactId>spring-plugin-core</artifactId>
148155
<version>${springframework-plugin.version}</version>
149156
</dependency>
157+
<dependency>
158+
<groupId>org.jetbrains.kotlin</groupId>
159+
<artifactId>kotlin-stdlib</artifactId>
160+
<version>${kotlin-stdlib.version}</version>
161+
</dependency>
150162
<dependency>
151163
<groupId>org.springframework.plugin</groupId>
152164
<artifactId>spring-plugin-metadata</artifactId>
@@ -307,6 +319,24 @@
307319
<groupId>org.springframework.security</groupId>
308320
<artifactId>spring-security-core</artifactId>
309321
<version>${spring.security.core.version}</version>
322+
<exclusions>
323+
<exclusion>
324+
<groupId>com.fasterxml.jackson.core</groupId>
325+
<artifactId>jackson-databind</artifactId>
326+
</exclusion>
327+
<exclusion>
328+
<groupId>org.springframework</groupId>
329+
<artifactId>spring-beans</artifactId>
330+
</exclusion>
331+
<exclusion>
332+
<groupId>org.springframework</groupId>
333+
<artifactId>spring-core</artifactId>
334+
</exclusion>
335+
<exclusion>
336+
<groupId>org.springframework</groupId>
337+
<artifactId>spring-expression</artifactId>
338+
</exclusion>
339+
</exclusions>
310340
</dependency>
311341
<dependency>
312342
<groupId>org.springframework.security</groupId>

0 commit comments

Comments
 (0)