update vulnerable dependencies
Upgraded dependencies to fix vulnerabilities. Migrated from springfox to springdoc, because springfox is not compatible with new version of spring boot.
Merge request reports
Activity
added Common Code MRBugfix Vulnerability Management labels
requested review from @ylesnikau, @malisherova, @nthakur, and @ajoshi19
assigned to @msavchuk
@msavchuk IBM is looking into this failure. As of now seems partition pod is failing to come up because of below error
Caused by: java.lang.ClassNotFoundException: org.springframework.data.repository.core.support.RepositoryMethodInvocationListener
Can you check in parallel which library upgrade might have introduced the same. cc @shrikgar @BdasIBM @ashwani_pandey to get their attention.@shrikgar @BdasIBM @ashwani_pandey I think the problem is in spring version upgrade. Also for this exception I found online that the problem might be in the spring versions mismatch between common poms and ibm pom
Edited by Mykyta Savchuk
mentioned in merge request !295 (merged)
@msavchuk We have made the necessary changes for IBM and verified the changes is working fine.
We have raised the below MR to merge the changes in fix_whitesource branch
changed milestone to %M15 - Release 0.18
added 7 commits
- 5b7b561e - IBM core lib upgrade
- f006d04f - Update buildspec
- e77a2cdf - GONRG 5799 upd google cloud pipeline
- b934ac69 - added changes to fix azure_code_coverage
- 5aaa4596 - GONRG-5965: Refactor PROJECT_ID variable for anthos/reference implementation
- ca0c88f1 - GONRG-5959 parameter partitionCleanUpEnabled is not described/used
- 608129b0 - Add secret name entity for bootstrap [GONRG-6060]
Toggle commit listHi this MR is targeted for M15 as indicated by the Milestone label. We are going to fork the release branch for M15 today. Please merge this MR if this is ready.
As per the PMC policy:
- For CSP-specific change, you can merge this once you get another approval from your team.
- For common code change, please ensure the pipelines are passing and we get approvals from the other CSPs.
- For lib upgrades/security fixes, you can merge make as long as the pipelines are passing,
Otherwise, please move this to the next milestone. Thank you.
added 28 commits
-
a39a777a...7c723fd3 - 24 commits from branch
master
- 58b39d08 - update vulnerable dependencies
- dda1f1f7 - upgrading spring-data-commons version
- a31699f5 - NOTICE update
- 1cf69f62 - Merge branch 'fix_whitesource' of...
Toggle commit list-
a39a777a...7c723fd3 - 24 commits from branch
added 2 commits
@msavchuk Can you help rebase and finalize this ?
added 12 commits
-
b2fac433...2c2d9c2a - 11 commits from branch
master
- 0982c649 - Resolve NOTICE merge conflicts
-
b2fac433...2c2d9c2a - 11 commits from branch
@msavchuk Can you help rebase and finalize this ?
added 5 commits
-
0982c649...e8530c3b - 4 commits from branch
master
- 87c43901 - Merge branch 'master' into 'fix_whitesource'
-
0982c649...e8530c3b - 4 commits from branch