diff --git a/build.gradle b/build.gradle index 823673288d..83a6da7961 100644 --- a/build.gradle +++ b/build.gradle @@ -141,19 +141,25 @@ subprojects { } implementation('net.minidev:json-smart') { version { - require '2.4.11' + require '2.5.0' } because 'CVE from transitive dependencies' } implementation('org.eclipse.jetty:jetty-http') { version { - require '11.0.15' + require '11.0.16' } because 'CVE from transitive dependencies' } implementation('org.eclipse.jetty:jetty-server') { version { - require '11.0.15' + require '11.0.16' + } + because 'CVE from transitive dependencies' + } + implementation('org.eclipse.jetty:jetty-servlets') { + version { + require '11.0.16' } because 'CVE from transitive dependencies' } @@ -169,6 +175,30 @@ subprojects { } because 'Fixes CVE-2023-35165, CVE-2023-34455, CVE-2023-34453, CVE-2023-34454, CVE-2023-2976' } + implementation('com.squareup.okio:okio-jvm') { + version { + require '3.5.0' + } + because 'CVE from transitive dependencies' + } + implementation('com.charleskorn.kaml:kaml') { + version { + require '0.55.0' + } + because 'CVE from transitive dependencies' + } + implementation('org.bitbucket.b_c:jose4j') { + version { + require '0.9.3' + } + because 'CVE from transitive dependencies' + } + implementation('org.scala-lang:scala-library') { + version { + require '2.13.12' + } + because 'CVE from transitive dependencies' + } } } diff --git a/settings.gradle b/settings.gradle index 42d6f96735..8a30c18fdc 100644 --- a/settings.gradle +++ b/settings.gradle @@ -21,7 +21,7 @@ dependencyResolutionManagement { library('armeria-core', 'com.linecorp.armeria', 'armeria').versionRef('armeria') library('armeria-grpc', 'com.linecorp.armeria', 'armeria-grpc').versionRef('armeria') library('armeria-junit', 'com.linecorp.armeria', 'armeria-junit5').versionRef('armeria') - version('protobuf', '3.21.11') + version('protobuf', '3.24.3') library('protobuf-core', 'com.google.protobuf', 'protobuf-java').versionRef('protobuf') library('protobuf-util', 'com.google.protobuf', 'protobuf-java-util').versionRef('protobuf') version('opentelemetry', '0.16.0-alpha') @@ -37,7 +37,7 @@ dependencyResolutionManagement { version('bouncycastle', '1.76') library('bouncycastle-bcprov', 'org.bouncycastle', 'bcprov-jdk18on').versionRef('bouncycastle') library('bouncycastle-bcpkix', 'org.bouncycastle', 'bcpkix-jdk18on').versionRef('bouncycastle') - version('guava', '32.0.1-jre') + version('guava', '32.1.2-jre') library('guava-core', 'com.google.guava', 'guava').versionRef('guava') library('commons-lang3', 'org.apache.commons', 'commons-lang3').version('3.13.0') }