|
36 | 36 | <junit.version>4.12</junit.version>
|
37 | 37 | <guava.version>32.0.1-jre</guava.version>
|
38 | 38 | <avro.version>1.8.1</avro.version>
|
| 39 | + <jackson.version>2.15.2</jackson.version> |
39 | 40 | <maven.release.plugin.version>2.5.3</maven.release.plugin.version>
|
40 | 41 | <!-- temporary fix by pinning the version until we upgrade to a version of common that contains this or newer version.
|
41 | 42 | See https://github.com/confluentinc/common/pull/332 for details -->
|
|
90 | 91 | </pluginRepository>
|
91 | 92 | </pluginRepositories>
|
92 | 93 |
|
| 94 | + |
| 95 | + <!-- pin transitive dependencies for CVEs --> |
| 96 | + <dependencyManagement> |
| 97 | + <dependencies> |
| 98 | + <dependency> |
| 99 | + <groupId>com.google.guava</groupId> |
| 100 | + <artifactId>guava</artifactId> |
| 101 | + <version>${guava.version}</version> |
| 102 | + </dependency> |
| 103 | + <dependency> |
| 104 | + <groupId>org.apache.httpcomponents</groupId> |
| 105 | + <artifactId>httpclient</artifactId> |
| 106 | + <version>${httpclient.version}</version> |
| 107 | + </dependency> |
| 108 | + <dependency> |
| 109 | + <groupId>com.fasterxml.jackson</groupId> |
| 110 | + <artifactId>jackson-bom</artifactId> |
| 111 | + <version>${jackson.version}</version> |
| 112 | + <type>pom</type> |
| 113 | + <scope>import</scope> |
| 114 | + </dependency> |
| 115 | + <dependency> |
| 116 | + <groupId>org.xerial.snappy</groupId> |
| 117 | + <artifactId>snappy-java</artifactId> |
| 118 | + <version>1.1.10.3</version> |
| 119 | + </dependency> |
| 120 | + </dependencies> |
| 121 | + </dependencyManagement> |
| 122 | + |
93 | 123 | <dependencies>
|
94 | 124 | <dependency>
|
95 | 125 | <groupId>org.apache.kafka</groupId>
|
|
111 | 141 | </exclusion>
|
112 | 142 | </exclusions>
|
113 | 143 | </dependency>
|
114 |
| - <dependency> |
115 |
| - <groupId>com.google.guava</groupId> |
116 |
| - <artifactId>guava</artifactId> |
117 |
| - <version>${guava.version}</version> |
118 |
| - </dependency> |
119 | 144 | <dependency>
|
120 | 145 | <groupId>junit</groupId>
|
121 | 146 | <artifactId>junit</artifactId>
|
|
0 commit comments