Skip to content

Commit 7ed3da9

Browse files
authored
Update indy-client, logback, slf4j and netty (#4375)
* Update indy-client, logback, slf4j and netty * Remove duplicate dependency declaration
1 parent 2866abc commit 7ed3da9

File tree

2 files changed

+12
-14
lines changed

2 files changed

+12
-14
lines changed

dto/pom.xml

Lines changed: 0 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -66,11 +66,6 @@
6666
<artifactId>jakarta.validation-api</artifactId>
6767
<scope>provided</scope>
6868
</dependency>
69-
<dependency>
70-
<groupId>org.hibernate.validator</groupId>
71-
<artifactId>hibernate-validator</artifactId>
72-
<scope>provided</scope>
73-
</dependency>
7469
<dependency>
7570
<groupId>commons-validator</groupId>
7671
<artifactId>commons-validator</artifactId>

pom.xml

Lines changed: 12 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -102,7 +102,7 @@
102102
<!--<version.org.jboss.spec.javax.jms.jboss-jms-api_2.0_spec>1.0.2.Final-redhat-1</version.org.jboss.spec.javax.jms.jboss-jms-api_2.0_spec>-->
103103
<version.org.jboss.spec.javax.jms.jboss-jms-api_1.1_spec>1.0.1.Final</version.org.jboss.spec.javax.jms.jboss-jms-api_1.1_spec>
104104
<atlasVersion>1.1.8</atlasVersion>
105-
<indyVersion>3.4.3</indyVersion>
105+
<indyVersion>3.4.5</indyVersion>
106106
<version.keycloak>18.0.11.redhat-00001</version.keycloak>
107107
<version.swagger2>2.2.37</version.swagger2>
108108
<version.buildagent>1.0.0</version.buildagent>
@@ -120,7 +120,6 @@
120120
<!-- -redhat version is missing some packages -->
121121
<version.com.github.json-patch>1.13</version.com.github.json-patch>
122122
<!-- SYNC commons-* with EAP provided versions (they can be found in eap-runtime-artifacts pom) -->
123-
<version.commons-lang>2.6</version.commons-lang>
124123
<version.commons-logging>1.3.5</version.commons-logging>
125124
<version.commons-collections>3.2.2</version.commons-collections>
126125
<version.commons-validator>1.9.0</version.commons-validator>
@@ -147,10 +146,11 @@
147146
<version.arquillian-jacoco>1.1.0</version.arquillian-jacoco>
148147
<version.arquillian-transactions>1.0.5</version.arquillian-transactions>
149148
<version.arquillian-wildfly>3.0.1.Final</version.arquillian-wildfly>
150-
<version.logback>1.2.3</version.logback>
149+
<version.logback>1.5.20</version.logback>
151150
<version.git-commit-id-plugin>4.9.10</version.git-commit-id-plugin>
152151
<version.maven-replacer-plugin>1.4.1</version.maven-replacer-plugin>
153152
<version.org.jsoup.jsoup>1.21.2</version.org.jsoup.jsoup>
153+
<version.org.slf4j>2.0.17</version.org.slf4j>
154154

155155
<datetime>${timestamp}</datetime>
156156
<pushChanges>true</pushChanges>
@@ -959,12 +959,6 @@
959959
<version>${version.com.fasterxml.jackson.datatype}</version>
960960
<scope>provided</scope>
961961
</dependency>
962-
<dependency>
963-
<groupId>commons-lang</groupId>
964-
<artifactId>commons-lang</artifactId>
965-
<version>${version.commons-lang}</version>
966-
<scope>provided</scope>
967-
</dependency>
968962

969963
<dependency>
970964
<groupId>commons-beanutils</groupId>
@@ -1151,6 +1145,15 @@
11511145
<artifactId>jsoup</artifactId>
11521146
<version>${version.org.jsoup.jsoup}</version>
11531147
</dependency>
1148+
1149+
<!-- Managing vulnerable versions of netty (4.1.84.Final) from vertx (from pnc rest-client) to avoid CVE -->
1150+
<dependency>
1151+
<groupId>io.netty</groupId>
1152+
<artifactId>netty-bom</artifactId>
1153+
<version>4.1.118.Final</version>
1154+
<type>pom</type>
1155+
<scope>import</scope>
1156+
</dependency>
11541157
</dependencies>
11551158
</dependencyManagement>
11561159

0 commit comments

Comments
 (0)