Skip to content

Commit bb881fe

Browse files
authored
📌 deps: Add assertj-core 3.27.7 as direct dependency (#1479)
1 parent a4b8d83 commit bb881fe

File tree

2 files changed

+43
-22
lines changed

2 files changed

+43
-22
lines changed

maven_plugin/lockfile.json

Lines changed: 36 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
"version": "5.12.2-SNAPSHOT",
99
"relativePath": "pom.xml",
1010
"checksumAlgorithm": "SHA-256",
11-
"checksum": "3f32c2ad121602278cee735c39a3573d3c472d6dd022fb7c3e119ad6a9b97e1e",
11+
"checksum": "f18a3b8ef415102d0530855ccdc5293337f2417ccb1590d5094d863a7c034b7f",
1212
"parent": {
1313
"groupId": "io.github.chains-project",
1414
"artifactId": "maven-lockfile-parent",
@@ -177,27 +177,11 @@
177177
"scope": "test",
178178
"resolved": "https://repo.maven.apache.org/maven2/org/assertj/assertj-core/3.24.2/assertj-core-3.24.2.jar",
179179
"repositoryId": "central",
180-
"selectedVersion": "3.24.2",
181-
"included": true,
180+
"selectedVersion": "3.27.7",
181+
"included": false,
182182
"id": "org.assertj:assertj-core:3.24.2",
183183
"parent": "com.soebes.itf.jupiter.extension:itf-assertj:0.13.1",
184-
"children": [
185-
{
186-
"groupId": "net.bytebuddy",
187-
"artifactId": "byte-buddy",
188-
"version": "1.12.21",
189-
"checksumAlgorithm": "SHA-256",
190-
"checksum": "f6f45c2237a7f132c16745ad2a52c4cdde58028b11ee80b09f0d422f4930d685",
191-
"scope": "test",
192-
"resolved": "https://repo.maven.apache.org/maven2/net/bytebuddy/byte-buddy/1.12.21/byte-buddy-1.12.21.jar",
193-
"repositoryId": "central",
194-
"selectedVersion": "1.15.11",
195-
"included": false,
196-
"id": "net.bytebuddy:byte-buddy:1.12.21",
197-
"parent": "org.assertj:assertj-core:3.24.2",
198-
"children": []
199-
}
200-
]
184+
"children": []
201185
}
202186
]
203187
},
@@ -1982,8 +1966,8 @@
19821966
"scope": "test",
19831967
"resolved": "https://repo.maven.apache.org/maven2/net/bytebuddy/byte-buddy/1.15.11/byte-buddy-1.15.11.jar",
19841968
"repositoryId": "central",
1985-
"selectedVersion": "1.15.11",
1986-
"included": true,
1969+
"selectedVersion": "1.18.3",
1970+
"included": false,
19871971
"id": "net.bytebuddy:byte-buddy:1.15.11",
19881972
"parent": "org.mockito:mockito-core:5.16.1",
19891973
"children": []
@@ -2384,6 +2368,36 @@
23842368
}
23852369
]
23862370
},
2371+
{
2372+
"groupId": "org.assertj",
2373+
"artifactId": "assertj-core",
2374+
"version": "3.27.7",
2375+
"checksumAlgorithm": "SHA-256",
2376+
"checksum": "c4a445426c3c2861666863b842cc4ec7bbb1c4226fefd370b6d2fe83d6c4ff0f",
2377+
"scope": "test",
2378+
"resolved": "https://repo.maven.apache.org/maven2/org/assertj/assertj-core/3.27.7/assertj-core-3.27.7.jar",
2379+
"repositoryId": "central",
2380+
"selectedVersion": "3.27.7",
2381+
"included": true,
2382+
"id": "org.assertj:assertj-core:3.27.7",
2383+
"children": [
2384+
{
2385+
"groupId": "net.bytebuddy",
2386+
"artifactId": "byte-buddy",
2387+
"version": "1.18.3",
2388+
"checksumAlgorithm": "SHA-256",
2389+
"checksum": "d78396e3c5bce3f2865c9186647481e5589d34cacc632484715b686108d17c66",
2390+
"scope": "test",
2391+
"resolved": "https://repo.maven.apache.org/maven2/net/bytebuddy/byte-buddy/1.18.3/byte-buddy-1.18.3.jar",
2392+
"repositoryId": "central",
2393+
"selectedVersion": "1.18.3",
2394+
"included": true,
2395+
"id": "net.bytebuddy:byte-buddy:1.18.3",
2396+
"parent": "org.assertj:assertj-core:3.27.7",
2397+
"children": []
2398+
}
2399+
]
2400+
},
23872401
{
23882402
"groupId": "org.instancio",
23892403
"artifactId": "instancio-junit",

maven_plugin/pom.xml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -88,6 +88,13 @@
8888
<version>6.0.2</version>
8989
<scope>test</scope>
9090
</dependency>
91+
<!-- Explicit dependency to fix GHSA-rqfh-9r24-8c9r (XXE vulnerability in versions < 3.27.7) -->
92+
<dependency>
93+
<groupId>org.assertj</groupId>
94+
<artifactId>assertj-core</artifactId>
95+
<version>3.27.7</version>
96+
<scope>test</scope>
97+
</dependency>
9198
<dependency>
9299
<groupId>org.apache.logging.log4j</groupId>
93100
<artifactId>log4j-core</artifactId>

0 commit comments

Comments
 (0)