From 02683c77bd93f45c2ec8a50c42668bbdad33a478 Mon Sep 17 00:00:00 2001 From: David Diederich <d.diederich@opengroup.org> Date: Mon, 20 Dec 2021 15:29:39 -1000 Subject: [PATCH] Upgrading library versions to incorporate the latest Log4j fix These updates apply version 2.17, addressing CVE-2021-45105 (cherry picked from commit 39c573bb915fc29e982c7a9938ca846c3978da35) Conflicts: indexer-core/pom.xml pom.xml provider/indexer-aws/pom.xml provider/indexer-azure/pom.xml provider/indexer-gcp/pom.xml provider/indexer-ibm/pom.xml testing/indexer-test-ibm/pom.xml --- indexer-core/pom.xml | 2 +- pom.xml | 4 ++-- provider/indexer-aws/pom.xml | 2 +- provider/indexer-azure/pom.xml | 6 +++--- provider/indexer-gcp/pom.xml | 2 +- provider/indexer-ibm/pom.xml | 2 +- testing/indexer-test-ibm/pom.xml | 2 +- 7 files changed, 10 insertions(+), 10 deletions(-) diff --git a/indexer-core/pom.xml b/indexer-core/pom.xml index 253486cc2..2340968d1 100644 --- a/indexer-core/pom.xml +++ b/indexer-core/pom.xml @@ -16,7 +16,7 @@ <properties> <commons-beanutils.version>1.9.4</commons-beanutils.version> - <osdu.oscorecommon.version>0.12.2</osdu.oscorecommon.version> + <osdu.oscorecommon.version>0.12.3</osdu.oscorecommon.version> </properties> <dependencies> diff --git a/pom.xml b/pom.xml index 57ba90bc2..a65a25b60 100644 --- a/pom.xml +++ b/pom.xml @@ -19,7 +19,7 @@ <java.version>1.8</java.version> <springfox-version>2.7.0</springfox-version> <spring-cloud.version>Greenwich.SR2</spring-cloud.version> - <os-core-common.version>0.12.2</os-core-common.version> + <os-core-common.version>0.12.3</os-core-common.version> <snakeyaml.version>1.26</snakeyaml.version> <hibernate-validator.version>6.1.5.Final</hibernate-validator.version> <jackson.version>2.11.4</jackson.version> @@ -29,7 +29,7 @@ <netty.version>4.1.51.Final</netty.version> <reactor-netty.version>0.8.20.RELEASE</reactor-netty.version> <woodstox-core.version>6.2.3</woodstox-core.version> - <log4j2.version>2.16.0</log4j2.version> + <log4j2.version>2.17.0</log4j2.version> <!-- <maven.compiler.target>1.8</maven.compiler.target>--> <!-- <maven.compiler.source>1.8</maven.compiler.source>--> <!-- <maven.war.plugin>2.6</maven.war.plugin>--> diff --git a/provider/indexer-aws/pom.xml b/provider/indexer-aws/pom.xml index 7bd6bf3d0..8f4d0c388 100644 --- a/provider/indexer-aws/pom.xml +++ b/provider/indexer-aws/pom.xml @@ -47,7 +47,7 @@ <dependency> <groupId>org.opengroup.osdu.core.aws</groupId> <artifactId>os-core-lib-aws</artifactId> - <version>0.12.2</version> + <version>0.12.3</version> </dependency> <!-- AWS managed packages --> diff --git a/provider/indexer-azure/pom.xml b/provider/indexer-azure/pom.xml index 98317c562..8daa86474 100644 --- a/provider/indexer-azure/pom.xml +++ b/provider/indexer-azure/pom.xml @@ -37,12 +37,12 @@ <azure.appservice.plan /> <azure.appservice.appname /> <azure.appservice.subscription /> - <log4j.version>2.16.0</log4j.version> + <log4j.version>2.17.0</log4j.version> <nimbus-jose-jwt.version>8.2</nimbus-jose-jwt.version> <indexer-core.version>0.12.3-SNAPSHOT</indexer-core.version> <spring-security-jwt.version>1.1.1.RELEASE</spring-security-jwt.version> - <osdu.corelibazure.version>0.12.3</osdu.corelibazure.version> - <osdu.oscorecommon.version>0.12.2</osdu.oscorecommon.version> + <osdu.corelibazure.version>0.12.4</osdu.corelibazure.version> + <osdu.oscorecommon.version>0.12.3</osdu.oscorecommon.version> <reactor-netty.version>0.9.12.RELEASE</reactor-netty.version> <java-jwt.version>3.8.1</java-jwt.version> <powermock.version>2.0.2</powermock.version> diff --git a/provider/indexer-gcp/pom.xml b/provider/indexer-gcp/pom.xml index fa59ee07d..6ea4482ac 100644 --- a/provider/indexer-gcp/pom.xml +++ b/provider/indexer-gcp/pom.xml @@ -19,7 +19,7 @@ <dependency> <groupId>org.opengroup.osdu</groupId> <artifactId>core-lib-gcp</artifactId> - <version>0.12.1</version> + <version>0.12.2</version> </dependency> <dependency> <groupId>org.opengroup.osdu.indexer</groupId> diff --git a/provider/indexer-ibm/pom.xml b/provider/indexer-ibm/pom.xml index b8446beb9..3779eddf6 100644 --- a/provider/indexer-ibm/pom.xml +++ b/provider/indexer-ibm/pom.xml @@ -31,7 +31,7 @@ <packaging>jar</packaging> <properties> - <os-core-lib-ibm.version>0.12.1</os-core-lib-ibm.version> + <os-core-lib-ibm.version>0.12.2</os-core-lib-ibm.version> </properties> <profiles> diff --git a/testing/indexer-test-ibm/pom.xml b/testing/indexer-test-ibm/pom.xml index 3624bc848..cb1a4f306 100644 --- a/testing/indexer-test-ibm/pom.xml +++ b/testing/indexer-test-ibm/pom.xml @@ -19,7 +19,7 @@ <maven.compiler.target>1.8</maven.compiler.target> <maven.compiler.source>1.8</maven.compiler.source> <cucumber.version>1.2.5</cucumber.version> - <os-core-lib-ibm.version>0.12.1</os-core-lib-ibm.version> + <os-core-lib-ibm.version>0.12.2</os-core-lib-ibm.version> </properties> <dependencies> -- GitLab