From f04332b67c2dd1494b3ef19117deada292ebf9e9 Mon Sep 17 00:00:00 2001 From: Ovidijus Narkevicius Date: Wed, 21 Feb 2024 14:51:29 +0200 Subject: [PATCH] fix: remove few old dependency constrains Closes: XRDDEV-2597 --- src/build.gradle | 24 ------------------------ src/gradle.properties | 5 +---- 2 files changed, 1 insertion(+), 28 deletions(-) diff --git a/src/build.gradle b/src/build.gradle index 2167a2a2f9..3c9640dfc7 100644 --- a/src/build.gradle +++ b/src/build.gradle @@ -133,30 +133,6 @@ configure(subprojects.findAll { !["shared-ui", "ui"].contains(it.name) }) { dependencies { //With require constraints we define lowest compliant dependency version (transitive dependencies are incl.) constraints { - add('implementation', 'com.fasterxml.jackson.core:jackson-databind') { - because("Vulnerability fix regarding CVE-2022-42003") - version { - require("$jacksonBomVersion") - } - } - add('implementation', 'org.yaml:snakeyaml') { - because("Vulnerability fix regarding CVE-2022-25857") - version { - require("$snakeyamlVersion") - } - } - add('implementation', 'org.apache.commons:commons-text') { - because("Vulnerability fix regarding CVE-2022-42889") - version { - require("$commonsTextVersion") - } - } - add('implementation', 'com.fasterxml.woodstox:woodstox-core') { - because("Vulnerability fix regarding CVE-2022-40152") - version { - require("$woodstoxVersion") - } - } add('implementation', 'io.micrometer:micrometer-tracing-bridge-brave') { because("Vulnerability fix regarding CVE-2022-47932") version { diff --git a/src/gradle.properties b/src/gradle.properties index 644f4da5cd..836fcfc0a8 100644 --- a/src/gradle.properties +++ b/src/gradle.properties @@ -23,15 +23,12 @@ mapStructVersion=1.5.5.Final shadowJarVersion=8.1.1 jacksonBomVersion=2.16.1 jackson-bom.version=${jacksonBomVersion} -snakeyamlVersion=2.2 -snakeyaml.version=${snakeyamlVersion} postgresqlVersion=42.6.1 postgresql.version=${postgresqlVersion} mockitoVersion=5.7.0 mockito.version=${mockitoVersion} cxfVersion=3.4.10 xercesVersion=2.12.2 -woodstoxVersion=6.4.0 springBootVersion=3.2.2 springDependenciesVersion=1.1.4 springSecurityVersion=6.2.2 @@ -64,7 +61,7 @@ openApiGeneratorVersion=7.1.0 swaggerParserVersion=2.1.20 hsqldbVersion=2.7.1:jdk8 hsqldb.version=${hsqldbVersion} -commonsTextVersion=1.10.0 +commonsTextVersion=1.11.0 commonsCliVersion=1.6.0 commonsCompressVersion=1.26.0 testAutomationFrameworkVersion=0.2.14