From 195398a7d99642d43cd23312c5f1347bbc722e03 Mon Sep 17 00:00:00 2001 From: Alex Porcelli Date: Tue, 12 Mar 2024 14:23:16 -0400 Subject: [PATCH 1/2] RHPAM-3709: upgrade maven dependencies to address CVE-2021-26291 --- mavenembedder-workitem/pom.xml | 21 ++++++++----------- pom.xml | 37 ---------------------------------- 2 files changed, 8 insertions(+), 50 deletions(-) diff --git a/mavenembedder-workitem/pom.xml b/mavenembedder-workitem/pom.xml index a661cc854..01ae8c82a 100644 --- a/mavenembedder-workitem/pom.xml +++ b/mavenembedder-workitem/pom.xml @@ -59,11 +59,11 @@ org.eclipse.sisu.plexus - org.sonatype.plexus + org.codehaus.plexus plexus-sec-dispatcher - org.sonatype.plexus + org.codehaus.plexus plexus-cipher @@ -114,23 +114,23 @@ provided - org.sonatype.plexus + org.codehaus.plexus plexus-sec-dispatcher provided - org.sonatype.plexus + org.codehaus.plexus plexus-cipher provided - org.eclipse.aether - aether-connector-basic + org.apache.maven.resolver + maven-resolver-connector-basic provided - org.eclipse.aether - aether-transport-wagon + org.apache.maven.resolver + maven-resolver-transport-wagon provided @@ -143,11 +143,6 @@ wagon-provider-api provided - - org.apache.maven.wagon - wagon-http-lightweight - provided - org.apache.commons commons-lang3 diff --git a/pom.xml b/pom.xml index c6cc7bfd9..7cbd54fff 100644 --- a/pom.xml +++ b/pom.xml @@ -56,11 +56,9 @@ 1.2.4 2.5.2.2 3.6 - 3.3.3 1.2.1.Final 3.2.2 2.5 - 3.3.9 1.1.4 9.1.15 1.67 @@ -472,41 +470,6 @@ commons-net ${version.commons.net} - - org.apache.maven - maven-embedder - ${version.maven.embedder} - - - org.eclipse.aether - aether-connector-basic - ${version.org.eclipse.aether} - - - org.eclipse.aether - aether-transport-wagon - ${version.org.eclipse.aether} - - - org.apache.maven.wagon - wagon-http - ${version.org.apache.maven.wagon} - - - org.apache.maven.wagon - wagon-provider-api - ${version.org.apache.maven.wagon} - - - org.apache.maven.wagon - wagon-http-lightweight - ${version.org.apache.maven.wagon} - - - org.apache.maven - maven-model - ${version.maven.model} - com.github.taycaldwell riot-api-java From 205dbb22cdd0f40c0f4a49d1707c26ba2916c52e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Tibor=20Zim=C3=A1nyi?= Date: Wed, 27 Mar 2024 10:00:57 +0100 Subject: [PATCH 2/2] Remove one unneeded dependency exclusion. --- jbpm-workitem-itests/pom.xml | 4 ---- 1 file changed, 4 deletions(-) diff --git a/jbpm-workitem-itests/pom.xml b/jbpm-workitem-itests/pom.xml index bd8f60c7d..245476a3d 100644 --- a/jbpm-workitem-itests/pom.xml +++ b/jbpm-workitem-itests/pom.xml @@ -116,10 +116,6 @@ org.hamcrest hamcrest - - org.springframework - spring-jcl - org.junit.jupiter junit-jupiter