Skip to content

Commit b28543b

Browse files
fix: update log4j (#38)
* fix: update log4j * fix: more vuln updates
1 parent d94d132 commit b28543b

File tree

2 files changed

+44
-35
lines changed

2 files changed

+44
-35
lines changed
Lines changed: 25 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -1,30 +1,36 @@
11
plugins {
2-
`java-library`
3-
jacoco
4-
id("org.hypertrace.publish-plugin")
5-
id("org.hypertrace.jacoco-report-plugin")
2+
`java-library`
3+
jacoco
4+
id("org.hypertrace.publish-plugin")
5+
id("org.hypertrace.jacoco-report-plugin")
66
}
77

88
tasks.test {
9-
useJUnitPlatform()
9+
useJUnitPlatform()
1010
}
1111

1212
dependencies {
13-
api(project(":kafka-streams-serdes"))
14-
api("com.typesafe:config:1.4.1")
15-
api("org.apache.kafka:kafka-streams:6.0.1-ccs")
16-
api("io.confluent:kafka-streams-avro-serde:6.0.1")
13+
api(project(":kafka-streams-serdes"))
14+
api("com.typesafe:config:1.4.1")
15+
api("org.apache.kafka:kafka-streams:6.0.1-ccs")
16+
api("io.confluent:kafka-streams-avro-serde:6.0.1")
1717

18-
implementation("com.google.guava:guava:30.1-jre")
19-
implementation("org.hypertrace.core.serviceframework:platform-metrics:0.1.23")
20-
implementation("org.hypertrace.core.serviceframework:platform-service-framework:0.1.23")
21-
implementation("org.apache.kafka:kafka-clients:6.0.1-ccs")
18+
implementation("com.google.guava:guava:30.1-jre")
19+
implementation("org.hypertrace.core.serviceframework:platform-metrics:0.1.31")
20+
implementation("org.hypertrace.core.serviceframework:platform-service-framework:0.1.31")
21+
implementation("org.apache.kafka:kafka-clients:6.0.1-ccs")
2222

23-
testImplementation("org.apache.kafka:kafka-streams-test-utils:6.0.1-ccs")
24-
testImplementation("org.junit.jupiter:junit-jupiter:5.7.0")
25-
testImplementation("org.junit-pioneer:junit-pioneer:1.1.0")
26-
testImplementation("org.mockito:mockito-core:3.6.28")
27-
testImplementation("org.hamcrest:hamcrest-core:2.2")
28-
testRuntimeOnly("org.apache.logging.log4j:log4j-slf4j-impl:2.14.0")
23+
constraints {
24+
api("org.glassfish.jersey.core:jersey-common:2.34") {
25+
because("https://snyk.io/vuln/SNYK-JAVA-ORGGLASSFISHJERSEYCORE-1255637")
26+
}
27+
}
28+
29+
testImplementation("org.apache.kafka:kafka-streams-test-utils:6.0.1-ccs")
30+
testImplementation("org.junit.jupiter:junit-jupiter:5.7.0")
31+
testImplementation("org.junit-pioneer:junit-pioneer:1.1.0")
32+
testImplementation("org.mockito:mockito-core:3.6.28")
33+
testImplementation("org.hamcrest:hamcrest-core:2.2")
34+
testRuntimeOnly("org.apache.logging.log4j:log4j-slf4j-impl:2.15.0")
2935
}
3036

Lines changed: 19 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -1,29 +1,32 @@
11
plugins {
2-
`java-library`
3-
jacoco
4-
id("org.hypertrace.avro-plugin")
5-
id("org.hypertrace.publish-plugin")
6-
id("org.hypertrace.jacoco-report-plugin")
2+
`java-library`
3+
jacoco
4+
id("org.hypertrace.avro-plugin")
5+
id("org.hypertrace.publish-plugin")
6+
id("org.hypertrace.jacoco-report-plugin")
77
}
88

99
tasks.test {
10-
useJUnitPlatform()
10+
useJUnitPlatform()
1111
}
1212

1313
dependencies {
14-
api("org.apache.kafka:kafka-streams:6.0.1-ccs")
15-
implementation("org.apache.avro:avro:1.10.2")
16-
implementation("org.apache.kafka:kafka-clients:6.0.1-ccs")
17-
testImplementation("org.junit.jupiter:junit-jupiter:5.7.0")
18-
constraints {
19-
api("com.fasterxml.jackson.core:jackson-databind:2.11.0") {
20-
because("XML External Entity (XXE) Injection (new) [High Severity][https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302] in com.fasterxml.jackson.core:[email protected]\n" +
21-
" introduced by com.fasterxml.jackson.core:[email protected]")
22-
}
14+
api("org.apache.kafka:kafka-streams:6.0.1-ccs")
15+
implementation("org.apache.avro:avro:1.10.2")
16+
implementation("org.apache.kafka:kafka-clients:6.0.1-ccs")
17+
testImplementation("org.junit.jupiter:junit-jupiter:5.7.0")
18+
constraints {
19+
api("com.fasterxml.jackson.core:jackson-databind:2.11.0") {
20+
because("XML External Entity (XXE) Injection (new) [High Severity][https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302] in com.fasterxml.jackson.core:[email protected]\n" +
21+
" introduced by com.fasterxml.jackson.core:[email protected]")
2322
}
23+
implementation("org.apache.commons:commons-compress:1.21") {
24+
because("Multiple Vulnerabilities [https://nvd.nist.gov/vuln/detail/CVE-2021-35515] [https://nvd.nist.gov/vuln/detail/CVE-2021-35516] [https://nvd.nist.gov/vuln/detail/CVE-2021-35517] [https://nvd.nist.gov/vuln/detail/CVE-2021-36090] in org.apache.commons:[email protected]")
25+
}
26+
}
2427
}
2528

2629
// Disabling compatibility check for the test avro definitions.
2730
tasks.named<org.hypertrace.gradle.avro.CheckAvroCompatibility>("avroCompatibilityCheck") {
28-
enabled = false
31+
enabled = false
2932
}

0 commit comments

Comments
 (0)