From 160ae68e618e1ecddc9a067a986b7c8c26ce457f Mon Sep 17 00:00:00 2001 From: Niranjana Date: Mon, 5 Jul 2021 05:56:31 +0000 Subject: Remove security vulnerabilities Issue-ID: DCAEGEN2-2809 Signed-off-by: Niranjana Change-Id: I2ec39bd685ba02681cecef01aa903584f0eed095 --- Changelog.md | 7 +- pom.xml | 572 +++++++++++++++++++++++++++++------------------------------ 2 files changed, 291 insertions(+), 288 deletions(-) diff --git a/Changelog.md b/Changelog.md index aa5c0c5..7387c84 100644 --- a/Changelog.md +++ b/Changelog.md @@ -4,4 +4,9 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](http://keepachangelog.com/) and this project adheres to [Semantic Versioning](http://semver.org/). -## [2.1.2] - 03/02/2021 \ No newline at end of file +## [2.1.4] - 21/06/2021 + - [DCAEGEN2-2711](https://jira.onap.org/browse/DCAEGEN2-2711) - Update sdk version to load policies from a file mounted by policy sidecar container + - [DCAEGEN2-2809](https://jira.onap.org/browse/DCAEGEN2-2809) - Remove security vulnerabilities + +## [2.1.3] - 03/02/2021 + - [DCAEGEN2-2599](https://jira.onap.org/browse/DCAEGEN2-2599) - Remove security vulnerabilities diff --git a/pom.xml b/pom.xml index 95aa1af..9e41846 100644 --- a/pom.xml +++ b/pom.xml @@ -4,7 +4,7 @@ * ============LICENSE_START======================================================= * son-handler * ================================================================================ - * Copyright (C) 2019-2020 Wipro Limited. + * Copyright (C) 2019-2021 Wipro Limited. * ============================================================================== * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -22,42 +22,43 @@ *******************************************************************************/ --> - 4.0.0 - org.onap.dcaegen2.services.son-handler - son-handler - dcaegen2-services-son-handler - 2.1.4-SNAPSHOT + xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd"> + 4.0.0 + org.onap.dcaegen2.services.son-handler + son-handler + dcaegen2-services-son-handler + 2.1.4-SNAPSHOT - + - - org.onap.oparent - oparent - 2.0.0 - - + + org.onap.oparent + oparent + 2.0.0 + + - - 1.8.6 - UTF-8 - 11 - 11 - onap/org.onap.dcaegen2.services.son-handler - - https://nexus.onap.org - content/repositories/snapshots/ - content/repositories/releases/ - content/sites/site/org/onap/dcaegen2/services/son-handler/${project.artifactId}/${project.version} - yyyyMMdd'T'HHmmss - - ${project.reporting.outputDirectory}/jacoco-ut/jacoco.xml - - + + 1.8.6 + 5.3.7 + UTF-8 + 11 + 11 + onap/org.onap.dcaegen2.services.son-handler + + https://nexus.onap.org + content/repositories/snapshots/ + content/repositories/releases/ + content/sites/site/org/onap/dcaegen2/services/son-handler/${project.artifactId}/${project.version} + yyyyMMdd'T'HHmmss + + ${project.reporting.outputDirectory}/jacoco-ut/jacoco.xml + + - + org.apache.tomcat @@ -71,171 +72,170 @@ 2.3.1.RELEASE - org.springframework - spring-webmvc - 5.2.10.RELEASE - + org.springframework + spring-webmvc + ${spring.version} + + + org.springframework + spring-core + ${spring.version} + + + org.springframework + spring-beans + ${spring.version} + - org.springframework - spring-core - 5.2.10.RELEASE - - - org.springframework - spring-beans - 5.2.10.RELEASE - - - org.springframework - spring-expression - 5.2.10.RELEASE + org.springframework + spring-expression + ${spring.version} + + + org.springframework + spring-web + ${spring.version} - - org.springframework - spring-web - 5.2.10.RELEASE - org.springframework spring-tx - 5.2.10.RELEASE + ${spring.version} org.springframework.data spring-data-commons 2.2.0.RELEASE - - - io.projectreactor.netty - reactor-netty - 0.9.12.RELEASE - - - - org.onap.dcaegen2.services.sdk.rest.services - cbs-client - ${sdk.version} - - - - org.onap.dcaegen2.services.sdk.security.crypt - crypt-password - ${sdk.version} - - - - org.springframework.boot - spring-boot-dependencies - 2.1.3.RELEASE - pom - import - - - com.att.nsa - cambriaClient - 0.0.1 - - - junit - junit - test - - - com.fasterxml.jackson.core - jackson-core - 2.11.0 - - - com.fasterxml.jackson.core - jackson-databind - 2.11.0 - - - - javax.json - javax.json-api - 1.1.2 - - - org.springframework.boot - spring-boot-starter-web - 2.1.3.RELEASE - - - org.springframework.boot - spring-boot-starter-tomcat - - - - - org.postgresql - postgresql - 42.2.18 - - - org.springframework.boot - spring-boot-starter-data-jpa - 2.1.3.RELEASE - - - org.hibernate.javax.persistence - hibernate-jpa-2.0-api - 1.0.1.Final - - - - org.springframework.boot - spring-boot-starter-test - 2.1.3.RELEASE - test - - - - - org.mockito - mockito-core - 2.21.0 - test - - - junit - junit - 4.12 - test - + + + io.projectreactor.netty + reactor-netty + 0.9.12.RELEASE + + + + org.onap.dcaegen2.services.sdk.rest.services + cbs-client + ${sdk.version} + + + org.onap.dcaegen2.services.sdk.security.crypt + crypt-password + ${sdk.version} + + + + org.springframework.boot + spring-boot-dependencies + 2.1.3.RELEASE + pom + import + + + com.att.nsa + cambriaClient + 0.0.1 + + + junit + junit + test + + + com.fasterxml.jackson.core + jackson-core + 2.11.0 + + + com.fasterxml.jackson.core + jackson-databind + 2.11.0 + + + + javax.json + javax.json-api + 1.1.2 + + + org.springframework.boot + spring-boot-starter-web + 2.1.3.RELEASE + + + org.springframework.boot + spring-boot-starter-tomcat + + + + + org.postgresql + postgresql + 42.2.18 + + + org.springframework.boot + spring-boot-starter-data-jpa + 2.1.3.RELEASE + + + org.hibernate.javax.persistence + hibernate-jpa-2.0-api + 1.0.1.Final + + + + org.springframework.boot + spring-boot-starter-test + 2.1.3.RELEASE + test + + + + + org.mockito + mockito-core + 2.21.0 + test + + + junit + junit + 4.12 + test + - - org.powermock - powermock-api-mockito2 - 2.0.2 - - - org.mockito - mockito-all - - - - - - org.powermock - powermock-module-junit4 - 2.0.2 - test - + + org.powermock + powermock-api-mockito2 + 2.0.2 + + + org.mockito + mockito-all + + + + + + org.powermock + powermock-module-junit4 + 2.0.2 + test + - - org.functionaljava - functionaljava - 3.0 + + org.functionaljava + functionaljava + 3.0 - - org.apache.httpcomponents - httpclient - 4.5.7 - + + org.apache.httpcomponents + httpclient + 4.5.13 + @@ -247,7 +247,7 @@ org.eclipse.jetty jetty-server - 9.4.17.v20190418 + 9.4.40.v20210413 @@ -267,116 +267,114 @@ javassist 3.24.1-GA - - org.apache.tomcat.embed - tomcat-embed-core - 9.0.39 - - + + org.apache.tomcat.embed + tomcat-embed-core + 9.0.46 + + - - + + - - - org.springframework.boot - spring-boot-maven-plugin - 2.3.1.RELEASE - - - - repackage - - - - - - com.spotify - docker-maven-plugin - - ${onap.nexus.dockerregistry.daily} + + + org.springframework.boot + spring-boot-maven-plugin + 2.3.1.RELEASE + + + + repackage + + + + + + com.spotify + docker-maven-plugin + + ${onap.nexus.dockerregistry.daily} - ${onap.nexus.dockerregistry.daily}/${docker.image.name} - + ${onap.nexus.dockerregistry.daily}/${docker.image.name} + ${project.version}-${maven.build.timestamp}Z ${project.version} latest - - openjdk:11.0.6-jre-slim - sonhms - - - /bin - ${project.build.directory} - ${project.artifactId}-${project.version}.jar - - - - - adduser --disabled-password sonhms - mv /bin/*.jar /bin/application.jar - chmod -R 777 /bin - - - 8080 - - java -jar /bin/application.jar - + + openjdk:11.0.6-jre-slim + sonhms + + + /bin + ${project.build.directory} + ${project.artifactId}-${project.version}.jar + + + + + adduser --disabled-password sonhms + mv /bin/*.jar /bin/application.jar + chmod -R 777 /bin + + + 8080 + + java -jar /bin/application.jar + - - - + + + - - -- cgit 1.2.3-korg