From a803e6761a04bcfd773f023e4fcce46482d8d4ba Mon Sep 17 00:00:00 2001 From: Alex Porcelli Date: Mon, 11 Mar 2024 17:04:28 -0400 Subject: [PATCH 1/3] RHPAM-3709: upgrade maven dependencies to address CVE-2021-26291 --- pom.xml | 130 ++++++++++++++++++++++++++++++++++++++------------------ 1 file changed, 88 insertions(+), 42 deletions(-) diff --git a/pom.xml b/pom.xml index 32facd7decf..e953f1e6c06 100644 --- a/pom.xml +++ b/pom.xml @@ -145,11 +145,11 @@ 4.4.14 2.4.0 6.6.6 - 3.3.9 - 3.2.1 + 3.8.6 + 3.3.4 3.3.0 3.4 - 3.0.0 + 3.5.1 3.1.1 4.1.2 2.9.2 @@ -165,22 +165,22 @@ 2.0.5 1.9.13 1.5.4 - 2.5.2 + 2.6.0 1.6 - 1.21 - 3.0.24 + 1.26 + 3.3.1 4.4.1 2.0M6 3.0 0.8.2-jboss - 1.1.0 + 1.6.3 2.6.0.v20100614-1136 2.5.0.v20100521-1846 3.18.0 9.4.53.v20231009 5.10.0.202012080955-r - 0.3.2 + 0.3.5 2.9.0 3.1.2 2.3.2 @@ -258,8 +258,8 @@ 1.0.3 1.7.30 1.13.1 - 1.7 - 1.3 + 2.0 + 2.0 2.3.0 3.2.3 5.3.27 @@ -352,7 +352,7 @@ 2.0.1.Final - 2.2.0 + 2.6.10 0.11.4.1 2.2.0 @@ -419,8 +419,7 @@ 1.13.5 3.0.0 - 0.9.1 - + 0.13.1 3.8.1 5.16.10 1.16.16 @@ -472,7 +471,7 @@ ${maven.multiModuleProjectDirectory} ${project.root.dir}/target/jacoco.exec - 1.8.0 + 1.15.0 v12.16.2 7.15.1 v1.22.4 @@ -3912,6 +3911,16 @@ org.apache.maven maven-embedder ${version.org.apache.maven} + + + javax.annotation + javax.annotation-api + + + javax.inject + javax.inject + + org.apache.maven @@ -3922,6 +3931,10 @@ javax.enterprise cdi-api + + javax.inject + javax.inject + @@ -3943,6 +3956,12 @@ org.apache.maven maven-model-builder ${version.org.apache.maven} + + + javax.inject + javax.inject + + org.apache.maven @@ -3951,8 +3970,14 @@ org.apache.maven - maven-aether-provider + maven-resolver-provider ${version.org.apache.maven} + + + javax.inject + javax.inject + + org.apache.maven @@ -3968,6 +3993,12 @@ org.apache.maven maven-settings-builder ${version.org.apache.maven} + + + javax.inject + javax.inject + + org.apache.maven.plugin-tools @@ -4356,52 +4387,55 @@ - org.eclipse.aether - aether-api - ${version.org.eclipse.aether} + org.apache.maven.resolver + maven-resolver-api + ${version.org.apache.maven.resolver} - org.eclipse.aether - aether-spi - ${version.org.eclipse.aether} + org.apache.maven.resolver + maven-resolver-spi + ${version.org.apache.maven.resolver} - org.eclipse.aether - aether-util - ${version.org.eclipse.aether} + org.apache.maven.resolver + maven-resolver-util + ${version.org.apache.maven.resolver} - org.eclipse.aether - aether-impl - ${version.org.eclipse.aether} + org.apache.maven.resolver + maven-resolver-impl + ${version.org.apache.maven.resolver} - org.eclipse.aether - aether-transport-file - ${version.org.eclipse.aether} + org.apache.maven.resolver + maven-resolver-transport-file + ${version.org.apache.maven.resolver} - org.eclipse.aether - aether-transport-http - ${version.org.eclipse.aether} + org.apache.maven.resolver + maven-resolver-transport-http + ${version.org.apache.maven.resolver} - org.eclipse.aether - aether-transport-wagon - ${version.org.eclipse.aether} + org.apache.maven.resolver + maven-resolver-transport-wagon + ${version.org.apache.maven.resolver} - org.eclipse.aether - aether-connector-basic - ${version.org.eclipse.aether} + org.apache.maven.resolver + maven-resolver-connector-basic + ${version.org.apache.maven.resolver} org.eclipse.sisu org.eclipse.sisu.plexus ${version.org.eclipse.sisu} - + + javax.annotation + javax.annotation-api + javax.enterprise cdi-api @@ -5176,14 +5210,26 @@ - org.sonatype.plexus + org.codehaus.plexus plexus-cipher ${version.org.sonatype.plexus.plexus-cipher} + + + javax.inject + javax.inject + + - org.sonatype.plexus + org.codehaus.plexus plexus-sec-dispatcher ${version.org.sonatype.plexus.plexus-sec-dispatcher} + + + javax.inject + javax.inject + + From fb3020d205f175e051a31af751379d0677034eca Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marek=20Novotn=C3=BD?= Date: Thu, 21 Mar 2024 15:19:21 +0100 Subject: [PATCH 2/3] upgrading version.org.jboss.shrinkwrap.resolver to 3.1.6 --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index e953f1e6c06..fef7c0bde97 100644 --- a/pom.xml +++ b/pom.xml @@ -205,7 +205,7 @@ 2.19.5.Final 2.0.5.Final 5.0.20.Final - 2.2.0 + 3.1.6 3.1.6.Final 3.1.SP3 1.6.5 From f81bee0a4361ff12faeceba0fe723564425468b6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tibor=20Zim=C3=A1nyi?= Date: Fri, 22 Mar 2024 10:42:15 +0100 Subject: [PATCH 3/3] Revert "upgrading version.org.jboss.shrinkwrap.resolver to 3.1.6" This reverts commit fb3020d205f175e051a31af751379d0677034eca. --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index fef7c0bde97..e953f1e6c06 100644 --- a/pom.xml +++ b/pom.xml @@ -205,7 +205,7 @@ 2.19.5.Final 2.0.5.Final 5.0.20.Final - 3.1.6 + 2.2.0 3.1.6.Final 3.1.SP3 1.6.5