Skip to content

Commit 6c55d58

Browse files
committed
fix sonatype reported cve issues
update version to 6.5.0-SNAPSHOT for next release
1 parent 25c4df1 commit 6c55d58

File tree

29 files changed

+52
-32
lines changed

29 files changed

+52
-32
lines changed

Diff for: bom/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@
2020
<parent>
2121
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2222
<artifactId>elasticactors-parent</artifactId>
23-
<version>6.4.4-SNAPSHOT</version>
23+
<version>6.5.0-SNAPSHOT</version>
2424
</parent>
2525
<modelVersion>4.0.0</modelVersion>
2626

Diff for: main/api/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/backplane-cassandra-common/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@
2020
<parent>
2121
<artifactId>elasticactors-main</artifactId>
2222
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
23-
<version>6.4.4-SNAPSHOT</version>
23+
<version>6.5.0-SNAPSHOT</version>
2424
</parent>
2525
<modelVersion>4.0.0</modelVersion>
2626

Diff for: main/backplane-cassandra/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/backplane-cassandra2/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/backplane-cassandra4/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@
2020
<parent>
2121
<artifactId>elasticactors-main</artifactId>
2222
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
23-
<version>6.4.4-SNAPSHOT</version>
23+
<version>6.5.0-SNAPSHOT</version>
2424
</parent>
2525
<modelVersion>4.0.0</modelVersion>
2626

Diff for: main/backplane-redis/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/base/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/caching/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/client-rabbitmq/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/client-spring-amqp/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/client/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/cluster-kubernetes/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@
2020
<parent>
2121
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2222
<artifactId>elasticactors-main</artifactId>
23-
<version>6.4.4-SNAPSHOT</version>
23+
<version>6.5.0-SNAPSHOT</version>
2424
</parent>
2525
<modelVersion>4.0.0</modelVersion>
2626

Diff for: main/cluster-shoal/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/core/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/elasticactors-kafka-testapp/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@
2020
<parent>
2121
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2222
<artifactId>elasticactors-main</artifactId>
23-
<version>6.4.4-SNAPSHOT</version>
23+
<version>6.5.0-SNAPSHOT</version>
2424
</parent>
2525
<modelVersion>4.0.0</modelVersion>
2626

Diff for: main/elasticactors-kafka/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/indexing-elasticsearch/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/messaging-activemq/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/messaging-rabbitmq/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/messaging/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/pom.xml

+23-3
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@
2121
<parent>
2222
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2323
<artifactId>elasticactors-parent</artifactId>
24-
<version>6.4.4-SNAPSHOT</version>
24+
<version>6.5.0-SNAPSHOT</version>
2525
</parent>
2626

2727
<artifactId>elasticactors-main</artifactId>
@@ -58,8 +58,7 @@
5858
<chronicle-bom.version>2.27ea8</chronicle-bom.version>
5959
<!-- this is needed to fix an issue with cassandra-driver-core 3.11.5 -->
6060
<jnr.version>2.2.16</jnr.version>
61-
<!-- This is the last release with ASLv2-->
62-
<elasticsearch.version>7.10.2</elasticsearch.version>
61+
<elasticsearch.version>7.17.27</elasticsearch.version>
6362
<kubernetes-client.version>7.0.1</kubernetes-client.version>
6463
<java-uuid-generator.version>5.1.0</java-uuid-generator.version>
6564
<!-- testing -->
@@ -79,6 +78,9 @@
7978
<fast-uuid.version>0.2.0</fast-uuid.version>
8079
<!-- needed to fix an issue with cassandra java-driver-core v4.17.0 and micrometer-core v1.13.0 -->
8180
<hdrhistogram.version>2.2.1</hdrhistogram.version>
81+
<!-- needed to fix sbom cve issues -->
82+
<libthrift.version>0.21.0</libthrift.version>
83+
<commons-lang3.version>3.17.0</commons-lang3.version>
8284
</properties>
8385

8486
<scm>
@@ -211,6 +213,16 @@
211213
</exclusion>
212214
</exclusions>
213215
</dependency>
216+
<dependency>
217+
<groupId>org.apache.thrift</groupId>
218+
<artifactId>libthrift</artifactId>
219+
<version>${libthrift.version}</version>
220+
</dependency>
221+
<dependency>
222+
<groupId>org.apache.commons</groupId>
223+
<artifactId>commons-lang3</artifactId>
224+
<version>${commons-lang3.version}</version>
225+
</dependency>
214226
<dependency>
215227
<groupId>org.apache.cassandra</groupId>
216228
<artifactId>cassandra-thrift</artifactId>
@@ -220,6 +232,10 @@
220232
<groupId>javax.servlet</groupId>
221233
<artifactId>servlet-api</artifactId>
222234
</exclusion>
235+
<exclusion>
236+
<groupId>org.apache.commons</groupId>
237+
<artifactId>commons-lang3</artifactId>
238+
</exclusion>
223239
</exclusions>
224240
</dependency>
225241
<dependency>
@@ -415,6 +431,10 @@
415431
<groupId>org.hdrhistogram</groupId>
416432
<artifactId>HdrHistogram</artifactId>
417433
</exclusion>
434+
<exclusion>
435+
<groupId>org.yaml</groupId>
436+
<artifactId>snakeyaml</artifactId>
437+
</exclusion>
418438
</exclusions>
419439
</dependency>
420440
<dependency>

Diff for: main/runtime/pom.xml

+2-2
Original file line numberDiff line numberDiff line change
@@ -19,12 +19,12 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

2626
<artifactId>elasticactors-runtime</artifactId>
27-
<version>6.4.4-SNAPSHOT</version>
27+
<version>6.5.0-SNAPSHOT</version>
2828
<packaging>jar</packaging>
2929

3030
<name>Elastic Software Foundation :: ElasticActors :: Runtime</name>

Diff for: main/spi/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/test/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/tracing-slf4j/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/tracing-spring/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: main/tracing/pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@
1919
<parent>
2020
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2121
<artifactId>elasticactors-main</artifactId>
22-
<version>6.4.4-SNAPSHOT</version>
22+
<version>6.5.0-SNAPSHOT</version>
2323
</parent>
2424
<modelVersion>4.0.0</modelVersion>
2525

Diff for: pom.xml

+1-1
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@
2020

2121
<groupId>org.elasticsoftwarefoundation.elasticactors</groupId>
2222
<artifactId>elasticactors-parent</artifactId>
23-
<version>6.4.4-SNAPSHOT</version>
23+
<version>6.5.0-SNAPSHOT</version>
2424

2525
<packaging>pom</packaging>
2626

0 commit comments

Comments
 (0)