File tree Expand file tree Collapse file tree 1 file changed +30
-5
lines changed Expand file tree Collapse file tree 1 file changed +30
-5
lines changed Original file line number Diff line number Diff line change 35
35
<junit .version>4.12</junit .version>
36
36
<guava .version>32.0.1-jre</guava .version>
37
37
<avro .version>1.8.1</avro .version>
38
+ <jackson .version>2.15.2</jackson .version>
38
39
<maven .release.plugin.version>2.5.3</maven .release.plugin.version>
39
40
</properties >
40
41
86
87
</pluginRepository >
87
88
</pluginRepositories >
88
89
90
+
91
+ <!-- pin transitive dependencies for CVEs -->
92
+ <dependencyManagement >
93
+ <dependencies >
94
+ <dependency >
95
+ <groupId >com.google.guava</groupId >
96
+ <artifactId >guava</artifactId >
97
+ <version >${guava.version} </version >
98
+ </dependency >
99
+ <dependency >
100
+ <groupId >org.apache.httpcomponents</groupId >
101
+ <artifactId >httpclient</artifactId >
102
+ <version >${httpclient.version} </version >
103
+ </dependency >
104
+ <dependency >
105
+ <groupId >com.fasterxml.jackson</groupId >
106
+ <artifactId >jackson-bom</artifactId >
107
+ <version >${jackson.version} </version >
108
+ <type >pom</type >
109
+ <scope >import</scope >
110
+ </dependency >
111
+ <dependency >
112
+ <groupId >org.xerial.snappy</groupId >
113
+ <artifactId >snappy-java</artifactId >
114
+ <version >1.1.10.3</version >
115
+ </dependency >
116
+ </dependencies >
117
+ </dependencyManagement >
118
+
89
119
<dependencies >
90
120
<dependency >
91
121
<groupId >org.apache.kafka</groupId >
107
137
</exclusion >
108
138
</exclusions >
109
139
</dependency >
110
- <dependency >
111
- <groupId >com.google.guava</groupId >
112
- <artifactId >guava</artifactId >
113
- <version >${guava.version} </version >
114
- </dependency >
115
140
<dependency >
116
141
<groupId >junit</groupId >
117
142
<artifactId >junit</artifactId >
You can’t perform that action at this time.
0 commit comments