Skip to content

Commit

Permalink
raise spring boot version, java-protobuf version to avoid vulnerabili…
Browse files Browse the repository at this point in the history
…ties
  • Loading branch information
ekl176 committed Jan 29, 2025
1 parent b5c3721 commit 298a6af
Show file tree
Hide file tree
Showing 2 changed files with 5 additions and 3 deletions.
2 changes: 1 addition & 1 deletion build.gradle.kts
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,6 @@ import com.adarshr.gradle.testlogger.theme.ThemeType
import com.github.jk1.license.filter.LicenseBundleNormalizer

buildscript { repositories { mavenCentral() } }

plugins {
alias(libs.plugins.spring.boot)
alias(libs.plugins.spring.dependency.management)
Expand Down Expand Up @@ -38,6 +37,7 @@ dependencies {
implementation(libs.spring.boot.starter.security)
implementation(libs.spring.boot.starter.web)
implementation(libs.spring.cloud.starter.kubernetes.client.config)
implementation(libs.google.java.protobuf)
implementation(libs.fitko.fitconnect.sdk)
compileOnly(libs.lombok)
developmentOnly(libs.spring.boot.devtools)
Expand Down
6 changes: 4 additions & 2 deletions gradle/libs.versions.toml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
[versions]
# @keep
jacoco = "0.8.12"
spring-boot = "3.3.5"
spring-boot = "3.4.2"

[libraries]
archunit-junit5 = "com.tngtech.archunit:archunit-junit5:1.3.0"
Expand All @@ -13,7 +13,9 @@ spring-boot-starter-actuator = { module = "org.springframework.boot:spring-boot-
spring-boot-starter-security = { module = "org.springframework.boot:spring-boot-starter-security" }
spring-boot-starter-web = { module = "org.springframework.boot:spring-boot-starter-web" }
spring-boot-starter-test = { module = "org.springframework.boot:spring-boot-starter-test" }
spring-cloud-starter-kubernetes-client-config = "org.springframework.cloud:spring-cloud-starter-kubernetes-client-config:3.1.4"
spring-cloud-starter-kubernetes-client-config = "org.springframework.cloud:spring-cloud-starter-kubernetes-client-config:3.2.0"
#pin transient client-config protobuf dependency version to avoid CVE-2024-7254
google-java-protobuf = "com.google.protobuf:protobuf-java:3.25.5"
spring-security-test = { module = "org.springframework.security:spring-security-test" }
fitko-fitconnect-sdk = "dev.fitko.fitconnect.sdk:client:2.5.0"
[plugins]
Expand Down

0 comments on commit 298a6af

Please sign in to comment.