diff options
-rw-r--r-- | CHANGELOG.md | 4 | ||||
-rw-r--r-- | pom.xml | 26 | ||||
-rw-r--r-- | version.properties | 2 |
3 files changed, 30 insertions, 2 deletions
diff --git a/CHANGELOG.md b/CHANGELOG.md index 8432e8b..1c27804 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,10 @@ and this project adheres to [Semantic Versioning](http://semver.org/). The version in the brackets represents the version of DCAE inventory and not the ONAP DCAE version. +## [3.0.1] + +* Explicitly use 5.3.6.Final for hibernate-validator and 9.4.6 for jetty-util to address security issues + ## [3.0.0] * Remove the dcae controller code (housekeeping) @@ -28,7 +28,7 @@ ECOMP is a trademark and service mark of AT&T Intellectual Property. <groupId>org.onap.dcaegen2.platform</groupId> <artifactId>inventory-api</artifactId> - <version>3.0.0</version> + <version>3.0.1</version> <name>dcaegen2-platform-inventory-api</name> <!--internal <version>3.0.0</version>--> @@ -68,6 +68,16 @@ ECOMP is a trademark and service mark of AT&T Intellectual Property. <groupId>io.dropwizard</groupId> <artifactId>dropwizard-core</artifactId> <version>${dropwizard.version}</version> + <exclusions> + <exclusion> + <groupId>org.hibernate</groupId> + <artifactId>hibernate-validator</artifactId> + </exclusion> + <exclusion> + <groupId>org.eclipse.jetty</groupId> + <artifactId>jetty-util</artifactId> + </exclusion> + </exclusions> </dependency> <dependency> <groupId>io.dropwizard</groupId> @@ -87,6 +97,20 @@ ECOMP is a trademark and service mark of AT&T Intellectual Property. <version>4.5.5</version> </dependency> <dependency> + <!-- To address security issue - CVE-2017-7536 --> + <groupId>org.hibernate</groupId> + <artifactId>hibernate-validator</artifactId> + <version>5.3.6.Final</version> + </dependency> + <dependency> + <!-- To address security issue - CVE-2017-9735 + REVIEW: Only updated jetty-util which may introduce runtime issues because + other jetty libraries are on 9.4.2 still --> + <groupId>org.eclipse.jetty</groupId> + <artifactId>jetty-util</artifactId> + <version>9.4.6.v20170531</version> + </dependency> + <dependency> <groupId>ch.qos.logback</groupId> <artifactId>logback-classic</artifactId> <version>${logback.version}</version> diff --git a/version.properties b/version.properties index fa21cfe..97784ff 100644 --- a/version.properties +++ b/version.properties @@ -3,7 +3,7 @@ # because they are used in Jenkins, whose plug-in doesn't support
major=3
minor=0
-patch=0
+patch=1
base_version=${major}.${minor}.${patch}
# Release must be completed with git revision # in Jenkins
|