Skip to content

Commit d659f59

Browse files
authored
2.x dependency upgrades (#10547)
* Upgrade apache commons-lang3 to 3.18.0 * Upgrades: gson to 2.13.1, jgit to 7.2.1, kafka client to 3.9.1, oci sdk to 3.68.0 * Upgrade owasp dependency check plugin to 12.1.3 * Upgrades jgit to 6.10.1 * Suppress jgit false postive * Suppress false positive for gRPC-C++
1 parent 74015a8 commit d659f59

File tree

3 files changed

+42
-6
lines changed

3 files changed

+42
-6
lines changed

dependencies/pom.xml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@
6262
<version.lib.graalvm>21.3.0</version.lib.graalvm>
6363
<version.lib.graphql-java>22.1</version.lib.graphql-java>
6464
<version.lib.graphql-java.extended.scalars>22.0</version.lib.graphql-java.extended.scalars>
65-
<version.lib.gson>2.9.0</version.lib.gson>
65+
<version.lib.gson>2.13.1</version.lib.gson>
6666
<version.lib.grpc>1.65.1</version.lib.grpc>
6767
<version.lib.guava>32.0.1-jre</version.lib.guava>
6868
<version.lib.h2>1.4.200</version.lib.h2>
@@ -87,13 +87,13 @@
8787
<version.lib.jaxb-runtime>2.3.3</version.lib.jaxb-runtime>
8888
<version.lib.jedis>3.6.3</version.lib.jedis>
8989
<version.lib.jersey>2.45</version.lib.jersey>
90-
<version.lib.jgit>6.7.0.202309050840-r</version.lib.jgit>
90+
<version.lib.jgit>6.10.1.202505221210-r</version.lib.jgit>
9191
<version.lib.jms-api>2.0</version.lib.jms-api>
9292
<version.lib.jsonb-api>1.0.2</version.lib.jsonb-api>
9393
<version.lib.jsonp-api>1.1.6</version.lib.jsonp-api>
9494
<version.lib.jsonp-impl>1.1.6</version.lib.jsonp-impl>
9595
<version.lib.junit>5.7.0</version.lib.junit>
96-
<version.lib.kafka>3.8.1</version.lib.kafka>
96+
<version.lib.kafka>3.9.1</version.lib.kafka>
9797
<version.lib.log4j>2.21.1</version.lib.log4j>
9898
<version.lib.logback>1.4.14</version.lib.logback>
9999
<version.lib.mariadb-java-client>2.6.2</version.lib.mariadb-java-client>
@@ -124,7 +124,7 @@
124124
<version.lib.narayana>5.12.0.Final</version.lib.narayana>
125125
<version.lib.netty>4.1.124.Final</version.lib.netty>
126126
<version.lib.netty-io_uring>0.0.19.Final</version.lib.netty-io_uring>
127-
<version.lib.oci>3.46.1</version.lib.oci>
127+
<version.lib.oci>3.68.0</version.lib.oci>
128128
<version.lib.oci-java-sdk-objectstorage>${version.lib.oci}</version.lib.oci-java-sdk-objectstorage>
129129
<version.lib.ojdbc8>21.15.0.0</version.lib.ojdbc8>
130130
<version.lib.database.messaging>19.3.0.0</version.lib.database.messaging>

etc/dependency-check-suppression.xml

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -214,6 +214,42 @@ https://github.com/jeremylong/DependencyCheck/issues/7019
214214
<cve>CVE-2025-30694</cve>
215215
</suppress>
216216

217+
<!-- False Positive.
218+
This CVE is against grpc/grpc C++ not gRPC Java
219+
https://github.com/grpc/grpc/issues/36245
220+
-->
221+
<suppress>
222+
<notes><![CDATA[
223+
file name: grpc-core-1.65.1.jar
224+
]]></notes>
225+
<packageUrl regex="true">^pkg:maven/io\.grpc/grpc.*@.*$</packageUrl>
226+
<cve>CVE-2024-7246</cve>
227+
</suppress>
228+
<!-- False Positive.
229+
This CVE is against gRPC-C++ - gRPC-C++ servers not gRPC Java
230+
https://github.com/grpc/grpc/issues/36245
231+
-->
232+
<suppress>
233+
<notes><![CDATA[
234+
file name: grpc-core-1.65.1.jar
235+
]]></notes>
236+
<packageUrl regex="true">^pkg:maven/io\.grpc/grpc.*@.*$</packageUrl>
237+
<cve>CVE-2024-11407</cve>
238+
</suppress>
239+
240+
241+
<!-- False Positive.
242+
jgit-6.10.1 has the fix for CVE-2025-4949. See
243+
https://projects.eclipse.org/projects/technology.jgit/releases/6.10.1
244+
-->
245+
<suppress>
246+
<notes><![CDATA[
247+
file name: org.eclipse.jgit-6.10.1.202505221210-r.jar
248+
]]></notes>
249+
<packageUrl regex="true">^pkg:maven/org\.eclipse\.jgit/org\.eclipse\.jgit@.*$</packageUrl>
250+
<cve>CVE-2025-4949</cve>
251+
</suppress>
252+
217253

218254

219255
</suppressions>

pom.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -82,7 +82,7 @@
8282
<version.lib.weld-junit>2.0.0.Final</version.lib.weld-junit>
8383
<version.lib.jmh>1.23</version.lib.jmh>
8484
<version.lib.wiremock>2.26.3</version.lib.wiremock>
85-
<version.lib.commons-lang3>3.10</version.lib.commons-lang3>
85+
<version.lib.commons-lang3>3.18.0</version.lib.commons-lang3>
8686
<version.lib.classgraph>4.8.165</version.lib.classgraph>
8787
<!--
8888
!Version statement! - end
@@ -118,7 +118,7 @@
118118
<version.plugin.source>3.0.1</version.plugin.source>
119119
<version.plugin.spotbugs>4.4.2.2</version.plugin.spotbugs>
120120
<version.plugin.findsecbugs>1.11.0</version.plugin.findsecbugs>
121-
<version.plugin.dependency-check>12.1.0</version.plugin.dependency-check>
121+
<version.plugin.dependency-check>12.1.3</version.plugin.dependency-check>
122122
<version.plugin.surefire>3.0.0-M5</version.plugin.surefire>
123123
<version.plugin.toolchains>1.1</version.plugin.toolchains>
124124
<version.plugin.version-plugin>2.3</version.plugin.version-plugin>

0 commit comments

Comments
 (0)