From 0b38dc2b9f1a45405dce1cb378f1a546a8c07411 Mon Sep 17 00:00:00 2001 From: Arvind Krishnakumar Date: Thu, 29 Jun 2023 09:18:45 -0500 Subject: [PATCH 1/2] Fix CVEs --- impl/pom.xml | 7 ++++++- integration-tests/pom.xml | 1 - pom.xml | 7 ++++++- src/owasp/owasp-suppression.xml | 25 +++---------------------- 4 files changed, 15 insertions(+), 25 deletions(-) diff --git a/impl/pom.xml b/impl/pom.xml index 5376011870a..4078651d079 100644 --- a/impl/pom.xml +++ b/impl/pom.xml @@ -109,7 +109,7 @@ org.powermock powermock-api-mockito2 - 2.0.4 + 2.0.9 test @@ -128,6 +128,11 @@ 9.30.2 test + + com.google.guava + guava + test + diff --git a/integration-tests/pom.xml b/integration-tests/pom.xml index 62e887124e4..072d744cc69 100644 --- a/integration-tests/pom.xml +++ b/integration-tests/pom.xml @@ -66,7 +66,6 @@ com.google.guava guava - 31.1-jre test diff --git a/pom.xml b/pom.xml index 04f53f15bb8..9b8b1c217d4 100644 --- a/pom.xml +++ b/pom.xml @@ -178,7 +178,12 @@ 1.1.0 true - + + com.google.guava + guava + 32.0.1-jre + test + org.testng testng diff --git a/src/owasp/owasp-suppression.xml b/src/owasp/owasp-suppression.xml index 09d7c907233..8f15c83d767 100644 --- a/src/owasp/owasp-suppression.xml +++ b/src/owasp/owasp-suppression.xml @@ -19,29 +19,10 @@ --> - + - - CVE-2016-1000027 - - - - - - CVE-2022-45688 - - - - - - CVE-2023-27162 - - - - - - CVE-2023-20860 - CVE-2023-20861 + + CVE-2023-35116 From d6fc242f699147f12a97cc61239a9a3d50e23ff1 Mon Sep 17 00:00:00 2001 From: Arvind Krishnakumar Date: Thu, 29 Jun 2023 09:43:03 -0500 Subject: [PATCH 2/2] updates --- impl/pom.xml | 27 +++++++++++++-------------- integration-tests/pom.xml | 6 ------ pom.xml | 3 ++- 3 files changed, 15 insertions(+), 21 deletions(-) diff --git a/impl/pom.xml b/impl/pom.xml index 4078651d079..00abfdb488f 100644 --- a/impl/pom.xml +++ b/impl/pom.xml @@ -87,12 +87,6 @@ javax.annotation-api true - - - com.google.auto.service - auto-service - true - @@ -131,19 +125,11 @@ com.google.guava guava - test - - src/main/resources - false - - **/version.properties - - src/main/resources true @@ -157,6 +143,19 @@ + + org.apache.maven.plugins + maven-compiler-plugin + + + + com.google.auto.service + auto-service + ${com.google.auto.service.version} + + + + org.codehaus.mojo build-helper-maven-plugin diff --git a/integration-tests/pom.xml b/integration-tests/pom.xml index 072d744cc69..d7e64b08bdf 100644 --- a/integration-tests/pom.xml +++ b/integration-tests/pom.xml @@ -68,12 +68,6 @@ guava test - - org.jboss.aerogear - aerogear-otp-java - 1.0.0 - test - de.sstoehr har-reader diff --git a/pom.xml b/pom.xml index 9b8b1c217d4..68dffb2755a 100644 --- a/pom.xml +++ b/pom.xml @@ -41,6 +41,7 @@ 5.2.1 11.0.3 1.3.3 + 1.1.1 okta/okta-sdk-java @@ -175,7 +176,7 @@ com.google.auto.service auto-service - 1.1.0 + ${com.google.auto.service.version} true