Skip to content

Remove SNAPSHOT dependencies

David Diederich requested to merge remove-snapshots into master

This automated MR removes usage of SNAPSHOT versions in the first party library dependencies. Since SNAPSHOT dependencies change frequently -- by their nature -- usage of them across projects is dangerous and should be avoided.

Dependency Information Before the Upgrade

Branch: master
SHA:    90491c9cf713c9a72937032181e242268de2d1ca
Maven:  0.18.0-SNAPSHOT
Maven Dependencies Root testing/
core-lib-azure 0.17.0-rc14
core-lib-gcp 0.16.0-rc1
os-core-lib-aws 0.17.0-SNAPSHOT 0.14.0-rc2
obm 0.15.0
oqm 0.15.0
os-core-common 0.17.0-rc3, 0.15.0 0.13.0
os-core-lib-ibm 0.16.0-rc1 0.13.0
osm 0.15.0
(3rd Party) com.fasterxml.jackson.core.jackson-databind 2.13.2.2 2.8.1, 2.13.2.2
(3rd Party) org.springframework.spring-webflux 5.3.12
(3rd Party) org.springframework.spring-webmvc 5.3.22, 5.1.19.RELEASE 5.3.12
Warning: Found Vulnerable Spring MVC dependency (<5.2.20 || >=5.3.0 <5.3.18)
├─ _Root_
│  ├─ org.opengroup.osdu.storage-byoc == 0.18.0-SNAPSHOT
│  │  └─ org.opengroup.osdu.storage-core == 0.18.0-SNAPSHOT
│  │     └─ org.springframework.spring-webmvc == 5.1.19.RELEASE
│  └─ org.opengroup.osdu.storage-ibm == 0.18.0-SNAPSHOT
│     └─ org.opengroup.osdu.storage-core == 0.18.0-SNAPSHOT
│        └─ org.springframework.spring-webmvc == 5.1.19.RELEASE
└─ testing/
├─ org.opengroup.osdu.storage.storage-test-core == 0.18.0-SNAPSHOT
│  └─ org.opengroup.osdu.os-core-common == 0.13.0
│     └─ org.springframework.boot.spring-boot-starter-web == 2.4.12
│        └─ org.springframework.spring-webmvc == 5.3.12
├─ org.opengroup.osdu.storage.storage-test-aws == 0.18.0-SNAPSHOT
│  └─ org.opengroup.osdu.os-core-common == 0.13.0
│     └─ org.springframework.boot.spring-boot-starter-web == 2.4.12
│        └─ org.springframework.spring-webmvc == 5.3.12
├─ org.opengroup.osdu.storage.storage-test-azure == 0.18.0-SNAPSHOT
│  └─ org.opengroup.osdu.storage.storage-test-core == 0.18.0-SNAPSHOT
│     └─ org.opengroup.osdu.os-core-common == 0.13.0
│        └─ org.springframework.boot.spring-boot-starter-web == 2.4.12
│           └─ org.springframework.spring-webmvc == 5.3.12
├─ org.opengroup.osdu.storage.storage-test-gcp == 0.18.0-SNAPSHOT
│  └─ org.opengroup.osdu.storage.storage-test-core == 0.18.0-SNAPSHOT
│     └─ org.opengroup.osdu.os-core-common == 0.13.0
│        └─ org.springframework.boot.spring-boot-starter-web == 2.4.12
│           └─ org.springframework.spring-webmvc == 5.3.12
├─ org.opengroup.osdu.storage.storage-test-ibm == 0.18.0-SNAPSHOT
│  └─ org.opengroup.osdu.os-core-common == 0.13.0
│     └─ org.springframework.boot.spring-boot-starter-web == 2.4.12
│        └─ org.springframework.spring-webmvc == 5.3.12
└─ org.opengroup.osdu.storage.storage-test-anthos == 0.18.0-SNAPSHOT
└─ org.opengroup.osdu.storage.storage-test-core == 0.18.0-SNAPSHOT
└─ org.opengroup.osdu.os-core-common == 0.13.0
└─ org.springframework.boot.spring-boot-starter-web == 2.4.12
└─ org.springframework.spring-webmvc == 5.3.12
Warning: Found Vulnerable Spring WebFlux dependency (<5.2.20 || >=5.3.0 <5.3.18)
└─ _Root_
└─ org.opengroup.osdu.storage-azure == 0.18.0-SNAPSHOT
└─ com.azure.spring.azure-spring-boot-starter-active-directory == 3.4.0
└─ org.springframework.boot.spring-boot-starter-webflux == 2.4.12
└─ org.springframework.spring-webflux == 5.3.12

Dependency Information After the Upgrade

Branch: remove-snapshots
SHA:    5b14fb922f3ed1d6a6e90e4fbe2178d6b8aab38c
Maven:  0.18.0-SNAPSHOT
Maven Dependencies Root testing/
core-lib-azure 0.17.0-rc14
core-lib-gcp 0.16.0-rc1
os-core-lib-aws 0.17.0 0.14.0-rc2
obm 0.15.0
oqm 0.15.0
os-core-common 0.17.0-rc3, 0.15.0 0.13.0
os-core-lib-ibm 0.16.0-rc1 0.13.0
osm 0.15.0
(3rd Party) com.fasterxml.jackson.core.jackson-databind 2.13.2.2 2.8.1, 2.13.2.2
(3rd Party) org.springframework.spring-webflux 5.3.12
(3rd Party) org.springframework.spring-webmvc 5.3.22, 5.1.19.RELEASE 5.3.12
Warning: Found Vulnerable Spring MVC dependency (<5.2.20 || >=5.3.0 <5.3.18)
├─ _Root_
│  ├─ org.opengroup.osdu.storage-byoc == 0.18.0-SNAPSHOT
│  │  └─ org.opengroup.osdu.storage-core == 0.18.0-SNAPSHOT
│  │     └─ org.springframework.spring-webmvc == 5.1.19.RELEASE
│  └─ org.opengroup.osdu.storage-ibm == 0.18.0-SNAPSHOT
│     └─ org.opengroup.osdu.storage-core == 0.18.0-SNAPSHOT
│        └─ org.springframework.spring-webmvc == 5.1.19.RELEASE
└─ testing/
├─ org.opengroup.osdu.storage.storage-test-core == 0.18.0-SNAPSHOT
│  └─ org.opengroup.osdu.os-core-common == 0.13.0
│     └─ org.springframework.boot.spring-boot-starter-web == 2.4.12
│        └─ org.springframework.spring-webmvc == 5.3.12
├─ org.opengroup.osdu.storage.storage-test-aws == 0.18.0-SNAPSHOT
│  └─ org.opengroup.osdu.os-core-common == 0.13.0
│     └─ org.springframework.boot.spring-boot-starter-web == 2.4.12
│        └─ org.springframework.spring-webmvc == 5.3.12
├─ org.opengroup.osdu.storage.storage-test-azure == 0.18.0-SNAPSHOT
│  └─ org.opengroup.osdu.storage.storage-test-core == 0.18.0-SNAPSHOT
│     └─ org.opengroup.osdu.os-core-common == 0.13.0
│        └─ org.springframework.boot.spring-boot-starter-web == 2.4.12
│           └─ org.springframework.spring-webmvc == 5.3.12
├─ org.opengroup.osdu.storage.storage-test-gcp == 0.18.0-SNAPSHOT
│  └─ org.opengroup.osdu.storage.storage-test-core == 0.18.0-SNAPSHOT
│     └─ org.opengroup.osdu.os-core-common == 0.13.0
│        └─ org.springframework.boot.spring-boot-starter-web == 2.4.12
│           └─ org.springframework.spring-webmvc == 5.3.12
├─ org.opengroup.osdu.storage.storage-test-ibm == 0.18.0-SNAPSHOT
│  └─ org.opengroup.osdu.os-core-common == 0.13.0
│     └─ org.springframework.boot.spring-boot-starter-web == 2.4.12
│        └─ org.springframework.spring-webmvc == 5.3.12
└─ org.opengroup.osdu.storage.storage-test-anthos == 0.18.0-SNAPSHOT
└─ org.opengroup.osdu.storage.storage-test-core == 0.18.0-SNAPSHOT
└─ org.opengroup.osdu.os-core-common == 0.13.0
└─ org.springframework.boot.spring-boot-starter-web == 2.4.12
└─ org.springframework.spring-webmvc == 5.3.12
Warning: Found Vulnerable Spring WebFlux dependency (<5.2.20 || >=5.3.0 <5.3.18)
└─ _Root_
└─ org.opengroup.osdu.storage-azure == 0.18.0-SNAPSHOT
└─ com.azure.spring.azure-spring-boot-starter-active-directory == 3.4.0
└─ org.springframework.boot.spring-boot-starter-webflux == 2.4.12
└─ org.springframework.spring-webflux == 5.3.12

Merge request reports