Skip to content

Commit 4afddef

Browse files
committed
"upgrade to the non-vulnerable dependency"
1 parent 7a056d2 commit 4afddef

File tree

4 files changed

+32
-21
lines changed

4 files changed

+32
-21
lines changed

build.gradle

Lines changed: 28 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,10 @@ artifactory {
4747

4848
nexusPublishing {
4949
repositories {
50-
sonatype()
50+
sonatype {
51+
nexusUrl.set(uri("https://ossrh-staging-api.central.sonatype.com/service/local/"))
52+
snapshotRepositoryUrl.set(uri("https://central.sonatype.com/repository/maven-snapshots/"))
53+
}
5154
}
5255
}
5356

@@ -61,23 +64,30 @@ subprojects {
6164
// Force secure versions to fix vulnerabilities
6265
configurations.all {
6366
resolutionStrategy {
64-
// Use latest confirmed available Jetty 9.4.x versions
65-
force 'org.eclipse.jetty:jetty-server:9.4.56.v20240826'
66-
force 'org.eclipse.jetty:jetty-servlets:9.4.56.v20240826'
67-
force 'org.eclipse.jetty:jetty-http:9.4.56.v20240826'
68-
force 'org.eclipse.jetty:jetty-util:9.4.56.v20240826'
69-
force 'org.eclipse.jetty:jetty-io:9.4.56.v20240826'
70-
force 'org.eclipse.jetty:jetty-client:9.4.56.v20240826'
71-
force 'org.eclipse.jetty:jetty-security:9.4.56.v20240826'
72-
force 'org.eclipse.jetty:jetty-servlet:9.4.56.v20240826'
73-
force 'org.eclipse.jetty:jetty-webapp:9.4.56.v20240826'
74-
force 'org.eclipse.jetty:jetty-proxy:9.4.56.v20240826'
75-
force 'org.eclipse.jetty:jetty-continuation:9.4.56.v20240826'
76-
force 'org.eclipse.jetty:jetty-util-ajax:9.4.56.v20240826'
77-
force 'org.eclipse.jetty:jetty-xml:9.4.56.v20240826'
78-
force 'org.eclipse.jetty.http2:http2-server:9.4.56.v20240826'
79-
force 'org.eclipse.jetty.http2:http2-common:9.4.56.v20240826'
80-
force 'org.eclipse.jetty.http2:http2-hpack:9.4.56.v20240826'
67+
// Use latest confirmed available Jetty 9.4.x versions - consistent versions
68+
force 'org.eclipse.jetty:jetty-server:9.4.58.v20250814'
69+
force 'org.eclipse.jetty:jetty-servlets:9.4.58.v20250814'
70+
force 'org.eclipse.jetty:jetty-http:9.4.58.v20250814'
71+
force 'org.eclipse.jetty:jetty-util:9.4.58.v20250814'
72+
force 'org.eclipse.jetty:jetty-io:9.4.58.v20250814'
73+
force 'org.eclipse.jetty:jetty-client:9.4.58.v20250814'
74+
force 'org.eclipse.jetty:jetty-security:9.4.58.v20250814'
75+
force 'org.eclipse.jetty:jetty-servlet:9.4.58.v20250814'
76+
force 'org.eclipse.jetty:jetty-webapp:9.4.58.v20250814'
77+
force 'org.eclipse.jetty:jetty-proxy:9.4.58.v20250814'
78+
force 'org.eclipse.jetty:jetty-continuation:9.4.58.v20250814'
79+
force 'org.eclipse.jetty:jetty-util-ajax:9.4.58.v20250814'
80+
force 'org.eclipse.jetty:jetty-xml:9.4.58.v20250814'
81+
force 'org.eclipse.jetty.http2:http2-server:9.4.58.v20250814'
82+
force 'org.eclipse.jetty.http2:http2-common:9.4.58.v20250814'
83+
force 'org.eclipse.jetty.http2:http2-hpack:9.4.58.v20250814'
84+
// Force ALPN modules that wiremock depends on
85+
force 'org.eclipse.jetty:jetty-alpn-server:9.4.58.v20250814'
86+
force 'org.eclipse.jetty:jetty-alpn-java-server:9.4.58.v20250814'
87+
force 'org.eclipse.jetty:jetty-alpn-openjdk8-server:9.4.58.v20250814'
88+
force 'org.eclipse.jetty:jetty-alpn-java-client:9.4.58.v20250814'
89+
force 'org.eclipse.jetty:jetty-alpn-openjdk8-client:9.4.58.v20250814'
90+
force 'org.eclipse.jetty:jetty-alpn-client:9.4.58.v20250814'
8191
// Latest secure versions
8292
force 'commons-io:commons-io:2.18.0'
8393
force 'net.minidev:json-smart:2.5.2'

gradle.properties

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
currentVersion=2.20.0
1+
currentVersion=2.20.2

release/pipelines.release.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,6 +12,7 @@ pipelines:
1212
readOnly:
1313
NEXT_VERSION: 0.0.0
1414
NEXT_DEVELOPMENT_VERSION: 0.0.x-SNAPSHOT
15+
AUDIT_FAIL: "false"
1516

1617
steps:
1718
- name: Release
@@ -54,7 +55,7 @@ pipelines:
5455
- git merge origin/dev
5556

5657
# Run audit
57-
- jf audit
58+
- jf audit --fail=${AUDIT_FAIL:-false}
5859

5960
# Update version
6061
- sed -i "s/\(currentVersion=\).*\$/\1${NEXT_VERSION}/" gradle.properties
Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
version=2.19.x-SNAPSHOT
1+
version=2.20.2

0 commit comments

Comments
 (0)