From 444e80c4cb8e8c1f610698e3ab7a30fa6ad74f51 Mon Sep 17 00:00:00 2001 From: Alex Porcelli Date: Mon, 11 Mar 2024 17:08:42 -0400 Subject: [PATCH 1/2] RHPAM-3709: upgrade maven dependencies to address CVE-2021-26291 --- kie-maven-plugin/pom.xml | 14 +++++--------- .../plugin/PackageKjarDependenciesMojo.java | 16 ++++++++-------- .../kie-server-integ-tests-all/pom.xml | 5 +++++ .../kie-server-integ-tests-controller/pom.xml | 6 ++++++ 4 files changed, 24 insertions(+), 17 deletions(-) diff --git a/kie-maven-plugin/pom.xml b/kie-maven-plugin/pom.xml index 9544f6ba9e..0084674c0a 100644 --- a/kie-maven-plugin/pom.xml +++ b/kie-maven-plugin/pom.xml @@ -70,6 +70,10 @@ + + jakarta.inject + jakarta.inject-api + org.apache.maven maven-artifact @@ -80,15 +84,7 @@ org.sonatype.sisu - sisu-guice - - - javax.inject - javax.inject - - - aopalliance - aopalliance + sisu-inject-plexus diff --git a/kie-maven-plugin/src/main/java/org/kie/maven/plugin/PackageKjarDependenciesMojo.java b/kie-maven-plugin/src/main/java/org/kie/maven/plugin/PackageKjarDependenciesMojo.java index 8a7227e7b1..9268a19016 100644 --- a/kie-maven-plugin/src/main/java/org/kie/maven/plugin/PackageKjarDependenciesMojo.java +++ b/kie-maven-plugin/src/main/java/org/kie/maven/plugin/PackageKjarDependenciesMojo.java @@ -50,14 +50,14 @@ import org.apache.maven.project.ProjectBuildingRequest; import org.apache.maven.repository.RepositorySystem; import org.apache.maven.settings.Settings; -import org.apache.maven.shared.artifact.ArtifactCoordinate; -import org.apache.maven.shared.artifact.DefaultArtifactCoordinate; -import org.apache.maven.shared.artifact.resolve.ArtifactResolver; -import org.apache.maven.shared.artifact.resolve.ArtifactResolverException; -import org.apache.maven.shared.artifact.resolve.ArtifactResult; -import org.apache.maven.shared.dependencies.DefaultDependableCoordinate; -import org.apache.maven.shared.dependencies.resolve.DependencyResolver; -import org.apache.maven.shared.dependencies.resolve.DependencyResolverException; +import org.apache.maven.shared.transfer.artifact.ArtifactCoordinate; +import org.apache.maven.shared.transfer.artifact.DefaultArtifactCoordinate; +import org.apache.maven.shared.transfer.artifact.resolve.ArtifactResolver; +import org.apache.maven.shared.transfer.artifact.resolve.ArtifactResolverException; +import org.apache.maven.shared.transfer.artifact.resolve.ArtifactResult; +import org.apache.maven.shared.transfer.dependencies.DefaultDependableCoordinate; +import org.apache.maven.shared.transfer.dependencies.resolve.DependencyResolver; +import org.apache.maven.shared.transfer.dependencies.resolve.DependencyResolverException; import org.apache.maven.shared.utils.StringUtils; import org.apache.maven.shared.utils.WriterFactory; import org.apache.maven.shared.utils.io.IOUtil; diff --git a/kie-server-parent/kie-server-tests/kie-server-integ-tests-all/pom.xml b/kie-server-parent/kie-server-tests/kie-server-integ-tests-all/pom.xml index 4b9b523fd8..344f02117f 100644 --- a/kie-server-parent/kie-server-tests/kie-server-integ-tests-all/pom.xml +++ b/kie-server-parent/kie-server-tests/kie-server-integ-tests-all/pom.xml @@ -114,6 +114,11 @@ test + + org.jsoup + jsoup + test + diff --git a/kie-server-parent/kie-server-tests/kie-server-integ-tests-controller/pom.xml b/kie-server-parent/kie-server-tests/kie-server-integ-tests-controller/pom.xml index 254ed90563..78d80ddf39 100644 --- a/kie-server-parent/kie-server-tests/kie-server-integ-tests-controller/pom.xml +++ b/kie-server-parent/kie-server-tests/kie-server-integ-tests-controller/pom.xml @@ -94,6 +94,12 @@ test + + org.jsoup + jsoup + test + + From 191d0c4748efabbcd2efabd4e56b3f8e1dfaf1d7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marek=20Novotn=C3=BD?= Date: Thu, 21 Mar 2024 15:25:19 +0100 Subject: [PATCH 2/2] adding exclusions for jcl-over-slf4j in jbpm-spring-boot-autoconfiguration org.slf4j jcl-over-slf4j --- .../jbpm-spring-boot-autoconfiguration/pom.xml | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/kie-spring-boot/kie-spring-boot-autoconfiguration/jbpm-spring-boot-autoconfiguration/pom.xml b/kie-spring-boot/kie-spring-boot-autoconfiguration/jbpm-spring-boot-autoconfiguration/pom.xml index 6a8b789123..3eb6e6424f 100644 --- a/kie-spring-boot/kie-spring-boot-autoconfiguration/jbpm-spring-boot-autoconfiguration/pom.xml +++ b/kie-spring-boot/kie-spring-boot-autoconfiguration/jbpm-spring-boot-autoconfiguration/pom.xml @@ -59,6 +59,12 @@ org.jbpm jbpm-workitems-rest + + + org.slf4j + jcl-over-slf4j + + org.jbpm @@ -95,6 +101,12 @@ org.jbpm jbpm-human-task-audit + + + org.slf4j + jcl-over-slf4j + + org.jbpm @@ -249,4 +261,4 @@ - \ No newline at end of file +