From e084d3afa3b1ba360c6d434692bfd8305502e3ef Mon Sep 17 00:00:00 2001 From: vv770d Date: Wed, 23 Feb 2022 21:33:11 +0000 Subject: Vulnerability updates for VES-mapper Change-Id: Idbeab8913bf25ac38e794320e363c12b8cc92704 Signed-off-by: vv770d Issue-ID: DCAEGEN2-3048 Signed-off-by: vv770d --- Changelog.md | 3 + UniversalVesAdapter/pom.xml | 792 ++++++++++++++++++++++---------------------- pom.xml | 8 +- 3 files changed, 403 insertions(+), 400 deletions(-) diff --git a/Changelog.md b/Changelog.md index b505bcb..65b0204 100644 --- a/Changelog.md +++ b/Changelog.md @@ -4,6 +4,9 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](http://keepachangelog.com/) and this project adheres to [Semantic Versioning](http://semver.org/). +## [1.3.3] - 2022/02/23 + - [DCAEGEN2-3048] - Vulnerability fixes for J release (xstream,jackson-core,jackson-databind,gson) + ## [1.3.2] - 2022/01/18 - [DCAEGEN2-3022] - Remediation for Log4Shell vulnerability (upgrade to 2.17.1) diff --git a/UniversalVesAdapter/pom.xml b/UniversalVesAdapter/pom.xml index e5169de..c08155c 100644 --- a/UniversalVesAdapter/pom.xml +++ b/UniversalVesAdapter/pom.xml @@ -22,413 +22,413 @@ --> - 4.0.0 + xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" + xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd"> + 4.0.0 - org.onap.dcaegen2.services.mapper.vesadapter - UniversalVesAdapter - 1.3.2-SNAPSHOT - - org.onap.dcaegen2.services.mapper - mapper - 1.3.2-SNAPSHOT - - + org.onap.dcaegen2.services.mapper.vesadapter + UniversalVesAdapter + 1.3.3-SNAPSHOT + + org.onap.dcaegen2.services.mapper + mapper + 1.3.3-SNAPSHOT + + - - UTF-8 - UTF-8 - 11 - onap/org.onap.dcaegen2.services.mapper.vesadapter.universalvesadaptor + + UTF-8 + UTF-8 + 11 + onap/org.onap.dcaegen2.services.mapper.vesadapter.universalvesadaptor - - false + + false - - https://nexus.onap.org - content/repositories/snapshots/ - content/repositories/releases/ - - content/sites/site/org/onap/dcaegen2/services/mapper/${project.artifactId}/${project.version} - - yyyyMMdd'T'HHmmss + + https://nexus.onap.org + content/repositories/snapshots/ + content/repositories/releases/ + + content/sites/site/org/onap/dcaegen2/services/mapper/${project.artifactId}/${project.version} + + yyyyMMdd'T'HHmmss - - 1.8.7 + + 1.8.7 - - - - - junit - junit - 4.12 - test - - - org.mockito - mockito-core - 2.0.5-beta - test - + + + + + junit + junit + 4.12 + test + + + org.mockito + mockito-core + 2.0.5-beta + test + - - org.powermock - powermock-api-mockito - 1.6.2 - test - - - org.powermock - powermock-module-junit4 - 1.6.2 - test - - - org.javassist - javassist - 3.27.0-GA - - - com.googlecode.json-simple - json-simple - 1.1.1 - - - com.google.guava - guava - - - commons-configuration - commons-configuration - 1.10 - - - com.google.code.gson - gson - 2.8.5 - - - com.google.inject - guice - 4.2.0 - - - org.apache.commons - commons-lang3 - 3.5 - - - com.google.inject.extensions - guice-assistedinject - 4.2.0 - - - org.milyn - milyn-smooks-all - 1.7.0 - - - javax.servlet - servlet-api - - - ognl - ognl - - - javax.jms - jms - - - - - ognl - ognl - 3.1.12 - - - org.onap.dmaap.messagerouter.dmaapclient - dmaapClient - 1.1.3 - - - javax.jms - jms - - - - - - org.postgresql - postgresql - 42.2.18 - - - org.springframework - spring-jdbc - 5.1.3.RELEASE - - - org.springframework.boot - spring-boot-starter-web - 2.1.1.RELEASE - - - org.springframework.boot - spring-boot-starter-test - 2.1.1.RELEASE - test - - - org.springframework.data - spring-data-commons - 2.1.3.RELEASE - - - - org.slf4j - slf4j-api - 1.7.25 - - - org.apache.logging.log4j - log4j-core - 2.17.1 - - - org.apache.logging.log4j - log4j-api - 2.17.1 - - - org.codehaus.groovy - groovy-all - 2.4.21 - - - com.jayway.jsonpath - json-path - 2.4.0 - test - - - com.fasterxml.jackson.core - jackson-core - 2.11.2 - - - com.fasterxml.jackson.core - jackson-databind - 2.11.2 - - - hsqldb - hsqldb - 1.8.0.10 - test - - - - xalan - xalan - 2.7.2 - - - - xerces - xercesImpl - 2.12.1 - - - - com.thoughtworks.xstream - xstream - 1.4.16 - - - - xml-apis - xml-apis - 1.4.01 - - - - org.apache.httpcomponents - httpclient - ${httpclient.version} - compile - - - org.apache.httpcomponents - httpmime - ${httpclient.version} - compile - - - org.springframework.boot - spring-boot-configuration-processor - true - 2.1.1.RELEASE - + + org.powermock + powermock-api-mockito + 1.6.2 + test + + + org.powermock + powermock-module-junit4 + 1.6.2 + test + + + org.javassist + javassist + 3.27.0-GA + + + com.googlecode.json-simple + json-simple + 1.1.1 + + + com.google.guava + guava + + + commons-configuration + commons-configuration + 1.10 + + + com.google.code.gson + gson + 2.8.9 + + + com.google.inject + guice + 4.2.0 + + + org.apache.commons + commons-lang3 + 3.5 + + + com.google.inject.extensions + guice-assistedinject + 4.2.0 + + + org.milyn + milyn-smooks-all + 1.7.0 + + + javax.servlet + servlet-api + + + ognl + ognl + + + javax.jms + jms + + + + + ognl + ognl + 3.1.12 + + + org.onap.dmaap.messagerouter.dmaapclient + dmaapClient + 1.1.3 + + + javax.jms + jms + + + + + + org.postgresql + postgresql + 42.2.18 + + + org.springframework + spring-jdbc + 5.1.3.RELEASE + + + org.springframework.boot + spring-boot-starter-web + 2.1.1.RELEASE + + + org.springframework.boot + spring-boot-starter-test + 2.1.1.RELEASE + test + + + org.springframework.data + spring-data-commons + 2.1.3.RELEASE + + + + org.slf4j + slf4j-api + 1.7.25 + + + org.apache.logging.log4j + log4j-core + 2.17.1 + + + org.apache.logging.log4j + log4j-api + 2.17.1 + + + org.codehaus.groovy + groovy-all + 2.4.21 + + + com.jayway.jsonpath + json-path + 2.4.0 + test + + + com.fasterxml.jackson.core + jackson-core + 2.12.6 + + + com.fasterxml.jackson.core + jackson-databind + 2.12.6 + + + hsqldb + hsqldb + 1.8.0.10 + test + + + + xalan + xalan + 2.7.2 + + + + xerces + xercesImpl + 2.12.1 + + + + com.thoughtworks.xstream + xstream + 1.4.18 + + + + xml-apis + xml-apis + 1.4.01 + + + + org.apache.httpcomponents + httpclient + ${httpclient.version} + compile + + + org.apache.httpcomponents + httpmime + ${httpclient.version} + compile + + + org.springframework.boot + spring-boot-configuration-processor + true + 2.1.1.RELEASE + - + - - org.onap.dcaegen2.services.sdk.rest.services - cbs-client - ${sdk.version} - - - - io.projectreactor.netty - reactor-netty - 0.9.12.RELEASE - - + + org.onap.dcaegen2.services.sdk.rest.services + cbs-client + ${sdk.version} + + + + io.projectreactor.netty + reactor-netty + 0.9.12.RELEASE + + - - - - - maven-assembly-plugin - 3.1.0 - - - com.spotify - docker-maven-plugin - 1.0.0 - - - - - - maven-assembly-plugin - - - src/assembly/dep.xml - - false - false - true - - - - make-assembly - package - - single - - - - - - com.spotify - docker-maven-plugin - 1.2.0 - - false - ${onap.nexus.dockerregistry.daily} - ${onap.nexus.dockerregistry.daily}/${docker.image.name} - - ${project.version}-${maven.build.timestamp}Z - ${project.version} - latest - - ${project.basedir}/src/main/docker - - - . - ${project.build.directory}/${project.artifactId}-${project.version} - - - - - - - org.springframework.boot - spring-boot-maven-plugin - 2.1.1.RELEASE - - - - repackage - - - org.onap.universalvesadapter.Application - - - - - - org.codehaus.mojo - build-helper-maven-plugin - 1.9.1 - - - add-source - generate-sources - - add-source - - - - src/gen/java - - - - - - - - - + + + + + maven-assembly-plugin + 3.1.0 + + + com.spotify + docker-maven-plugin + 1.0.0 + + + + + + maven-assembly-plugin + + + src/assembly/dep.xml + + false + false + true + + + + make-assembly + package + + single + + + + + + com.spotify + docker-maven-plugin + 1.2.0 + + false + ${onap.nexus.dockerregistry.daily} + ${onap.nexus.dockerregistry.daily}/${docker.image.name} + + ${project.version}-${maven.build.timestamp}Z + ${project.version} + latest + + ${project.basedir}/src/main/docker + + + . + ${project.build.directory}/${project.artifactId}-${project.version} + + + + + + + org.springframework.boot + spring-boot-maven-plugin + 2.1.1.RELEASE + + + + repackage + + + org.onap.universalvesadapter.Application + + + + + + org.codehaus.mojo + build-helper-maven-plugin + 1.9.1 + + + add-source + generate-sources + + add-source + + + + src/gen/java + + + + + + + + + - - - with-system-proxy - - - - com.spotify - docker-maven-plugin - - - ${env.http_proxy} - - - - - - - + + + with-system-proxy + + + + com.spotify + docker-maven-plugin + + + ${env.http_proxy} + + + + + + + - - - spring-releases - https://repo.spring.io/libs-release - - - - - spring-releases - https://repo.spring.io/libs-release - - + + + spring-releases + https://repo.spring.io/libs-release + + + + + spring-releases + https://repo.spring.io/libs-release + + diff --git a/pom.xml b/pom.xml index f358125..a94f919 100644 --- a/pom.xml +++ b/pom.xml @@ -32,7 +32,7 @@ org.onap.dcaegen2.services.mapper mapper - 1.3.2-SNAPSHOT + 1.3.3-SNAPSHOT pom dcaegen2-services-mapper @@ -124,9 +124,9 @@ content/sites/site/org/onap/dcaegen2/services/mapper/${project.artifactId}/${project.version} - - ${project.reporting.outputDirectory}/jacoco-ut/jacoco.xml - + + ${project.reporting.outputDirectory}/jacoco-ut/jacoco.xml + -- cgit 1.2.3-korg