File tree Expand file tree Collapse file tree 4 files changed +14
-3
lines changed
Expand file tree Collapse file tree 4 files changed +14
-3
lines changed Original file line number Diff line number Diff line change 5454 steps :
5555 - name : Dependency Check
5656 uses : hypertrace/github-actions/dependency-check@main
57+ with :
58+ nvd-api-key : ${{ secrets.NVD_API_KEY }}
Original file line number Diff line number Diff line change @@ -7,7 +7,7 @@ plugins {
77 id(" org.hypertrace.publish-plugin" ) version " 1.0.2" apply false
88 id(" org.hypertrace.jacoco-report-plugin" ) version " 0.2.1" apply false
99 id(" org.hypertrace.code-style-plugin" ) version " 1.1.2" apply false
10- id(" org.owasp.dependencycheck" ) version " 8.3.1 "
10+ id(" org.owasp.dependencycheck" ) version " 12.1.0 "
1111}
1212
1313subprojects {
Original file line number Diff line number Diff line change 11<?xml version =" 1.0" encoding =" UTF-8" ?>
22<suppressions xmlns =" https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd" >
3+ <suppress until =" 2025-05-31Z" >
4+ <notes ><![CDATA[
5+ file name: micrometer-registry-prometheus-simpleclient-1.14.4.jar, fix not available yet
6+ ]]> </notes >
7+ <packageUrl regex =" true" >^pkg:maven/io\.micrometer/micrometer-registry-prometheus-simpleclient@.*$</packageUrl >
8+ <cve >CVE-2019-3826</cve >
9+ </suppress >
310</suppressions >
Original file line number Diff line number Diff line change @@ -12,10 +12,12 @@ tasks.test {
1212dependencies {
1313 api(" com.typesafe:config:1.4.2" )
1414 api(" io.dropwizard.metrics:metrics-jakarta-servlet:4.2.25" )
15- api(" io.micrometer:micrometer-core:1.10.2 " )
15+ api(" io.micrometer:micrometer-core:1.14.4 " )
1616 api(" jakarta.servlet:jakarta.servlet-api:6.0.0" )
1717
18- implementation(" io.micrometer:micrometer-registry-prometheus:1.10.2" )
18+ // Using simpleclient flavour since with version >= 1.13.0 micrometer does not support io.prometheus.simpleclient dependencies
19+ // https://github.com/micrometer-metrics/micrometer/wiki/1.13-Migration-Guide
20+ implementation(" io.micrometer:micrometer-registry-prometheus-simpleclient:1.14.4" )
1921
2022 implementation(" io.github.mweirauch:micrometer-jvm-extras:0.2.2" )
2123 implementation(" org.slf4j:slf4j-api:1.7.36" )
You can’t perform that action at this time.
0 commit comments