Skip to content

Upgrade vulnerable dependencies according to WhiteSource alerts

Dmitrii Gerashchenko requested to merge 6912-whitesource into master

Issue: #52 (closed)

WhiteSource's Security vulnerabilities list contains alerts:

  • spring-web-5.3.6.jar
  • netty-codec-4.1.63.Final.jar
  • netty-codec-4.1.63.Final.jar
  • spring-security-oauth2-client-5.4.6.jar
  • netty-all-4.1.63.Final.jar
  • netty-handler-4.1.63.Final.jar
  • gson-2.8.5.jar
  • json-smart-2.4.2.jar

Alerts descriptions:


Updates:

  • spring-boot.version: 2.4.5 -> 2.4.12
  • netty-bom.version: 4.1.63.Final -> 4.1.70.Final
  • json-smart.version: 2.4.7
  • gson.version: 2.8.5 -> 2.8.9

Successful pipeline: https://community.opengroup.org/osdu/platform/system/lib/core/os-core-common/-/pipelines/77632

screenshotimage

Related MRs:

Edited by Dmitrii Gerashchenko

Merge request reports