Skip to content

Commit 11f4cf2

Browse files
committed
fix CVE-2023-2976 and upgrade guava to be consistent
Signed-off-by: Xun Zhang <xunzh@amazon.com>
1 parent b84b130 commit 11f4cf2

File tree

5 files changed

+8
-4
lines changed

5 files changed

+8
-4
lines changed

build.gradle

+4
Original file line numberDiff line numberDiff line change
@@ -67,6 +67,10 @@ subprojects {
6767
configurations {
6868
testImplementation.extendsFrom compileOnly
6969
}
70+
71+
configurations.all {
72+
resolutionStrategy.force "com.google.guava:guava:32.1.2-jre"
73+
}
7074
}
7175

7276
ext {

memory/build.gradle

+1-1
Original file line numberDiff line numberDiff line change
@@ -28,7 +28,7 @@ dependencies {
2828
implementation group: 'org.opensearch', name: 'opensearch', version: "${opensearch_version}"
2929
implementation group: 'org.apache.httpcomponents.core5', name: 'httpcore5', version: '5.2.2'
3030
implementation "org.opensearch:common-utils:${common_utils_version}"
31-
implementation group: 'com.google.guava', name: 'guava', version: '32.0.1-jre'
31+
implementation group: 'com.google.guava', name: 'guava', version: '32.1.2-jre'
3232
testImplementation (group: 'junit', name: 'junit', version: '4.13.2') {
3333
exclude module : 'hamcrest'
3434
exclude module : 'hamcrest-core'

ml-algorithms/build.gradle

+1-1
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,7 @@ dependencies {
4242
implementation group: 'io.protostuff', name: 'protostuff-collectionschema', version: '1.8.0'
4343
testImplementation group: 'junit', name: 'junit', version: '4.13.2'
4444
testImplementation group: 'org.mockito', name: 'mockito-core', version: '5.7.0'
45-
implementation group: 'com.google.guava', name: 'guava', version: '32.0.1-jre'
45+
implementation group: 'com.google.guava', name: 'guava', version: '32.1.2-jre'
4646
implementation group: 'com.google.code.gson', name: 'gson', version: '2.10.1'
4747
implementation platform("ai.djl:bom:0.21.0")
4848
implementation group: 'ai.djl.pytorch', name: 'pytorch-model-zoo', version: '0.21.0'

plugin/build.gradle

+1-1
Original file line numberDiff line numberDiff line change
@@ -57,7 +57,7 @@ dependencies {
5757
implementation "org.opensearch:common-utils:${common_utils_version}"
5858
implementation("com.fasterxml.jackson.core:jackson-annotations:${versions.jackson}")
5959
implementation("com.fasterxml.jackson.core:jackson-databind:${versions.jackson_databind}")
60-
implementation group: 'com.google.guava', name: 'guava', version: '32.0.1-jre'
60+
implementation group: 'com.google.guava', name: 'guava', version: '32.1.2-jre'
6161
implementation group: 'com.google.code.gson', name: 'gson', version: '2.10.1'
6262
implementation group: 'org.apache.commons', name: 'commons-lang3', version: '3.10'
6363
implementation group: 'org.apache.commons', name: 'commons-math3', version: '3.6.1'

search-processors/build.gradle

+1-1
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ dependencies {
3636
implementation group: 'org.opensearch', name: 'common-utils', version: "${common_utils_version}"
3737
// https://mvnrepository.com/artifact/org.apache.httpcomponents.core5/httpcore5
3838
implementation group: 'org.apache.httpcomponents.core5', name: 'httpcore5', version: '5.2.2'
39-
implementation("com.google.guava:guava:32.0.1-jre")
39+
implementation group: 'com.google.guava', name: 'guava', version: '32.1.2-jre'
4040
implementation group: 'org.json', name: 'json', version: '20231013'
4141
implementation group: 'org.apache.commons', name: 'commons-text', version: '1.10.0'
4242
testImplementation "org.opensearch.test:framework:${opensearch_version}"

0 commit comments

Comments
 (0)