Skip to content

Commit e3d0cb9

Browse files
ENG-58332:Upgrade Micrometer version (#115)
* upgrade micrometer version * use key * update version * version change * version change * suppress
1 parent 0530d03 commit e3d0cb9

File tree

4 files changed

+14
-3
lines changed

4 files changed

+14
-3
lines changed

.github/workflows/build-and-test.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -54,3 +54,5 @@ jobs:
5454
steps:
5555
- name: Dependency Check
5656
uses: hypertrace/github-actions/dependency-check@main
57+
with:
58+
nvd-api-key: ${{ secrets.NVD_API_KEY }}

build.gradle.kts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ plugins {
77
id("org.hypertrace.publish-plugin") version "1.0.2" apply false
88
id("org.hypertrace.jacoco-report-plugin") version "0.2.1" apply false
99
id("org.hypertrace.code-style-plugin") version "1.1.2" apply false
10-
id("org.owasp.dependencycheck") version "8.3.1"
10+
id("org.owasp.dependencycheck") version "12.1.0"
1111
}
1212

1313
subprojects {

owasp-suppressions.xml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,10 @@
11
<?xml version="1.0" encoding="UTF-8"?>
22
<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
3+
<suppress until="2025-05-31Z">
4+
<notes><![CDATA[
5+
file name: micrometer-registry-prometheus-simpleclient-1.14.4.jar, fix not available yet
6+
]]></notes>
7+
<packageUrl regex="true">^pkg:maven/io\.micrometer/micrometer-registry-prometheus-simpleclient@.*$</packageUrl>
8+
<cve>CVE-2019-3826</cve>
9+
</suppress>
310
</suppressions>

platform-metrics/build.gradle.kts

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,10 +12,12 @@ tasks.test {
1212
dependencies {
1313
api("com.typesafe:config:1.4.2")
1414
api("io.dropwizard.metrics:metrics-jakarta-servlet:4.2.25")
15-
api("io.micrometer:micrometer-core:1.10.2")
15+
api("io.micrometer:micrometer-core:1.14.4")
1616
api("jakarta.servlet:jakarta.servlet-api:6.0.0")
1717

18-
implementation("io.micrometer:micrometer-registry-prometheus:1.10.2")
18+
// Using simpleclient flavour since with version >= 1.13.0 micrometer does not support io.prometheus.simpleclient dependencies
19+
// https://github.com/micrometer-metrics/micrometer/wiki/1.13-Migration-Guide
20+
implementation("io.micrometer:micrometer-registry-prometheus-simpleclient:1.14.4")
1921

2022
implementation("io.github.mweirauch:micrometer-jvm-extras:0.2.2")
2123
implementation("org.slf4j:slf4j-api:1.7.36")

0 commit comments

Comments
 (0)