From eb66bd0e23b1abc91454d0a4d4210b775d5dbe5d Mon Sep 17 00:00:00 2001 From: Mohammad Arshad Date: Tue, 3 Sep 2024 09:11:45 +0530 Subject: [PATCH] [Improvement] [Seatunnel-web] velocity-1.7.jar have multiple CVEs, upgrade all maven plugins which depend on this. (#202) --- pom.xml | 17 ++++++++++++++--- tools/dependencies/known-dependencies.txt | 4 ++-- 2 files changed, 16 insertions(+), 5 deletions(-) diff --git a/pom.xml b/pom.xml index df7621ed5..e0df3bf20 100644 --- a/pom.xml +++ b/pom.xml @@ -51,7 +51,7 @@ 3.0.1 2.22.2 2.22.2 - 2.9.1 + 3.10.0 3.10.1 3.3.0 3.2.0 @@ -84,6 +84,8 @@ true 3.1.1 1.3.0 + 3.2.0 + 4.0.0-M16 2.6.8 5.3.20 @@ -103,9 +105,8 @@ 3.1.4 1.11.271 2.29.0 - 1.2.11 + 1.5.7 2.17.1 - 1.2.3 1.2 1.2.17 2.17.1 @@ -1546,6 +1547,16 @@ com.diffplug.spotless spotless-maven-plugin + + org.apache.maven.plugins + maven-remote-resources-plugin + ${maven-remote-resources-plugin.version} + + + org.apache.maven.plugins + maven-site-plugin + ${maven-site-plugin.version} + diff --git a/tools/dependencies/known-dependencies.txt b/tools/dependencies/known-dependencies.txt index c6a0d02f9..28e6b0b2b 100644 --- a/tools/dependencies/known-dependencies.txt +++ b/tools/dependencies/known-dependencies.txt @@ -106,8 +106,8 @@ jcommander-1.81.jar log4j-api-2.17.1.jar log4j-over-slf4j-1.7.36.jar log4j-to-slf4j-2.17.1.jar -logback-classic-1.2.3.jar -logback-core-1.2.3.jar +logback-classic-1.5.7.jar +logback-core-1.5.7.jar protostuff-api-1.8.0.jar protostuff-collectionschema-1.8.0.jar protostuff-core-1.8.0.jar