Skip to content

Commit db5d1bb

Browse files
authored
Merge pull request #4805 from nscuro/bump-deps-
Bump dependencies that Dependabot missed
2 parents 4379049 + 47f4ae3 commit db5d1bb

1 file changed

Lines changed: 9 additions & 27 deletions

File tree

pom.xml

Lines changed: 9 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -87,22 +87,22 @@
8787
<!-- Dependency Versions -->
8888
<frontend.version>4.12.7</frontend.version>
8989
<lib.alpine.version>${project.parent.version}</lib.alpine.version>
90-
<lib.awaitility.version>4.2.2</lib.awaitility.version>
90+
<lib.awaitility.version>4.3.0</lib.awaitility.version>
9191
<lib.brotli-decoder.version>0.1.2</lib.brotli-decoder.version>
92-
<lib.checkstyle.version>10.20.2</lib.checkstyle.version>
92+
<lib.checkstyle.version>10.22.0</lib.checkstyle.version>
9393
<lib.aws-advanced-jdbc-wrapper.version>2.5.5</lib.aws-advanced-jdbc-wrapper.version>
9494
<lib.cloud-sql-connector-jdbc-sqlserver.version>1.24.1</lib.cloud-sql-connector-jdbc-sqlserver.version>
95-
<lib.cloud-sql-mysql-socket-factory-connector-j-8.version>1.21.0</lib.cloud-sql-mysql-socket-factory-connector-j-8.version>
96-
<lib.cloud-sql-postgres-socket-factory.version>1.21.0</lib.cloud-sql-postgres-socket-factory.version>
95+
<lib.cloud-sql-mysql-socket-factory-connector-j-8.version>1.24.1</lib.cloud-sql-mysql-socket-factory-connector-j-8.version>
96+
<lib.cloud-sql-postgres-socket-factory.version>1.24.1</lib.cloud-sql-postgres-socket-factory.version>
9797
<lib.cpe-parser.version>3.0.0</lib.cpe-parser.version>
9898
<lib.commons-compress.version>1.27.1</lib.commons-compress.version>
9999
<lib.commons-text.version>1.13.0</lib.commons-text.version>
100100
<lib.cvss-calculator.version>1.4.2</lib.cvss-calculator.version>
101101
<lib.owasp-rr-calculator.version>1.0.1</lib.owasp-rr-calculator.version>
102-
<lib.cyclonedx-java.version>9.1.0</lib.cyclonedx-java.version>
102+
<lib.cyclonedx-java.version>10.2.1</lib.cyclonedx-java.version>
103103
<lib.greenmail.version>2.1.3</lib.greenmail.version>
104-
<lib.jackson.version>2.18.0</lib.jackson.version>
105-
<lib.jackson-databind.version>2.18.0</lib.jackson-databind.version>
104+
<lib.jackson.version>2.18.3</lib.jackson.version>
105+
<lib.jackson-databind.version>2.18.3</lib.jackson-databind.version>
106106
<lib.json-java.version>20250107</lib.json-java.version>
107107
<lib.json-unit.version>4.1.0</lib.json-unit.version>
108108
<lib.junit.version>4.13.2</lib.junit.version>
@@ -114,7 +114,7 @@
114114
<lib.pebble.version>3.2.3</lib.pebble.version>
115115
<lib.protobuf-java.version>4.30.2</lib.protobuf-java.version>
116116
<lib.resilience4j.version>2.2.0</lib.resilience4j.version>
117-
<lib.swagger-parser.version>2.1.22</lib.swagger-parser.version>
117+
<lib.swagger-parser.version>2.1.25</lib.swagger-parser.version>
118118
<lib.system-rules.version>1.19.0</lib.system-rules.version>
119119
<lib.testcontainers.version>1.20.6</lib.testcontainers.version>
120120
<lib.wiremock.version>2.35.2</lib.wiremock.version>
@@ -128,7 +128,7 @@
128128
<!-- JDBC Drivers -->
129129
<lib.jdbc-driver.mssql.version>12.10.0.jre11</lib.jdbc-driver.mssql.version>
130130
<lib.jdbc-driver.mysql.version>8.2.0</lib.jdbc-driver.mysql.version>
131-
<lib.jdbc-driver.postgresql.version>42.7.4</lib.jdbc-driver.postgresql.version>
131+
<lib.jdbc-driver.postgresql.version>42.7.5</lib.jdbc-driver.postgresql.version>
132132
<!-- Maven Plugin Properties -->
133133
<plugin.retirejs.breakOnFailure>false</plugin.retirejs.breakOnFailure>
134134
<plugin.jetty.version>12.0.18</plugin.jetty.version>
@@ -153,24 +153,6 @@
153153
</repository>
154154
</repositories>
155155

156-
<dependencyManagement>
157-
<dependencies>
158-
<!--
159-
Resolve CVE-2024-57699 (https://github.com/advisories/GHSA-pq2g-wx69-c263).
160-
Highly unlikely to be exploitable in DT or Alpine, but we're bumping the
161-
version anyway since the update is low-risk and reduces scanner noise.
162-
163-
TODO: Remove this when bumping Alpine to >= 3.2.0, which includes a version
164-
of com.nimbusds:oauth2-oidc-sdk pulling in a newer json-smart version, too.
165-
-->
166-
<dependency>
167-
<groupId>net.minidev</groupId>
168-
<artifactId>json-smart</artifactId>
169-
<version>2.5.2</version>
170-
</dependency>
171-
</dependencies>
172-
</dependencyManagement>
173-
174156
<dependencies>
175157
<!-- Alpine -->
176158
<dependency>

0 commit comments

Comments
 (0)