Skip to content

Commit b87ae34

Browse files
Update cosmos commons lang 3 version (#46100)
* Updated commons lang3 library to 3.18.0 * Reverted cosmos commons lang3 to central repo commons lang3 to fix CVE
1 parent 7dc5b58 commit b87ae34

File tree

3 files changed

+3
-4
lines changed

3 files changed

+3
-4
lines changed

eng/versioning/external_dependencies.txt

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -252,7 +252,6 @@ cosmos_org.mpierce.metrics.reservoir:hdrhistogram-metrics-reservoir;1.1.0
252252
cosmos_org.hdrhistogram:HdrHistogram;2.1.12
253253
cosmos_com.fasterxml.jackson.core:jackson-databind;2.15.2
254254
cosmos_com.fasterxml.jackson.module:jackson-module-scala_2.12;2.15.2
255-
cosmos_org.apache.commons:commons-lang3;3.12.0
256255

257256
## Cosmos Spark connector under sdk\cosmos\azure-cosmos-spark_3-<version>_2-12\pom.xml
258257
# Cosmos Spark connector runtime dependencies - provided by Spark runtime/host

sdk/cosmos/azure-cosmos-benchmark/pom.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -152,7 +152,7 @@ Licensed under the MIT License.
152152
<dependency>
153153
<groupId>org.apache.commons</groupId>
154154
<artifactId>commons-lang3</artifactId>
155-
<version>3.12.0</version> <!-- {x-version-update;cosmos_org.apache.commons:commons-lang3;external_dependency} -->
155+
<version>3.18.0</version> <!-- {x-version-update;org.apache.commons:commons-lang3;external_dependency} -->
156156
</dependency>
157157

158158
<dependency>
@@ -276,7 +276,7 @@ Licensed under the MIT License.
276276
<include>io.micrometer:micrometer-core:[1.15.1]</include> <!-- {x-include-update;cosmos_io.micrometer:micrometer-core;external_dependency} -->
277277
<include>io.micrometer:micrometer-registry-azure-monitor:[1.15.1]</include> <!-- {x-include-update;cosmos_io.micrometer:micrometer-registry-azure-monitor;external_dependency} -->
278278
<include>io.micrometer:micrometer-registry-graphite:[1.15.1]</include> <!-- {x-include-update;cosmos_io.micrometer:micrometer-registry-graphite;external_dependency} -->
279-
<include>org.apache.commons:commons-lang3:[3.12.0]</include> <!-- {x-include-update;cosmos_org.apache.commons:commons-lang3;external_dependency} -->
279+
<include>org.apache.commons:commons-lang3:[3.18.0]</include> <!-- {x-include-update;org.apache.commons:commons-lang3;external_dependency} -->
280280
<include>org.apache.logging.log4j:log4j-api:[2.17.2]</include> <!-- {x-include-update;org.apache.logging.log4j:log4j-api;external_dependency} -->
281281
<include>org.apache.logging.log4j:log4j-core:[2.17.2]</include> <!-- {x-include-update;org.apache.logging.log4j:log4j-core;external_dependency} -->
282282
<include>org.apache.logging.log4j:log4j-slf4j-impl:[2.17.2]</include> <!-- {x-include-update;org.apache.logging.log4j:log4j-slf4j-impl;external_dependency} -->

sdk/cosmos/azure-cosmos-spark_3_2-12/pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -310,7 +310,7 @@
310310
<rules>
311311
<bannedDependencies>
312312
<includes>
313-
<include>org.apache.commons:commons-lang3:[3.12.0]</include> <!-- {x-include-update;cosmos_org.apache.commons:commons-lang3;external_dependency} -->
313+
<include>org.apache.commons:commons-lang3:[3.18.0]</include> <!-- {x-include-update;org.apache.commons:commons-lang3;external_dependency} -->
314314
<include>org.slf4j:slf4j-api:[1.7.36]</include> <!-- {x-include-update;org.slf4j:slf4j-api;external_dependency} -->
315315
<include>org.apache.spark:spark-sql_2.12:[3.3.0]</include> <!-- {x-include-update;cosmos-spark_3-3_org.apache.spark:spark-sql_2.12;external_dependency} -->
316316
<include>org.apache.spark:spark-sql_2.12:[3.4.0]</include> <!-- {x-include-update;cosmos-spark_3-4_org.apache.spark:spark-sql_2.12;external_dependency} -->

0 commit comments

Comments
 (0)