Skip to content

Commit

Permalink
Upgrade Spring Boot dependency version to 3.2.1
Browse files Browse the repository at this point in the history
- Upgrade Spring Framework dependency version to 6.1.2
- Upgrade Spring Data BOM dependency version to 2023.1.1
- Upgrade Spring Cloud version to 2023.0.0
- Clean up dependency suppressions
  • Loading branch information
ghillert committed Jan 2, 2024
1 parent 229dc8a commit fd66d51
Show file tree
Hide file tree
Showing 3 changed files with 13 additions and 30 deletions.
11 changes: 5 additions & 6 deletions pom.xml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
<?xml version="1.0" encoding="UTF-8"?>

<!--
Copyright (c) 2013, 2023, Oracle and/or its affiliates.
Copyright (c) 2013, 2024, Oracle and/or its affiliates.
Licensed under the Universal Permissive License v 1.0 as shown at
https://oss.oracle.com/licenses/upl.
-->
Expand Down Expand Up @@ -166,14 +166,13 @@
<log4j.version>2.21.1</log4j.version>
<mockito.version>5.7.0</mockito.version>
<modelmapper.version>3.1.1</modelmapper.version>
<org.springframework.version>6.1.1</org.springframework.version>
<org.springframework.data.version>2023.1.0</org.springframework.data.version>
<org.springframework.version>6.1.2</org.springframework.version>
<reactor.version>3.6.1</reactor.version>
<resilience4j.version>2.1.0</resilience4j.version>
<slf4j-api.version>2.0.9</slf4j-api.version>
<spring-boot.version>3.2.0</spring-boot.version>
<spring-boot.version>3.2.1</spring-boot.version>
<spring-cloud.version>2023.0.0</spring-cloud.version>
<spring-data-bom.version>2023.1.0</spring-data-bom.version>
<spring-data-bom.version>2023.1.1</spring-data-bom.version>
<spring-session.version>3.2.0</spring-session.version>
<spring-security.version>6.1.5</spring-security.version>
<tomcat.version>10.1.16</tomcat.version>
Expand Down Expand Up @@ -250,7 +249,7 @@
<dependency>
<groupId>org.springframework.data</groupId>
<artifactId>spring-data-bom</artifactId>
<version>${org.springframework.data.version}</version>
<version>${spring-data-bom.version}</version>
<type>pom</type>
<scope>import</scope>
</dependency>
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
<?xml version="1.0" encoding="UTF-8"?>

<!--
Copyright (c) 2021, 2023, Oracle and/or its affiliates.
Copyright (c) 2021, 2024, Oracle and/or its affiliates.
Licensed under the Universal Permissive License v 1.0 as shown at
https://oss.oracle.com/licenses/upl.
-->
Expand All @@ -25,7 +25,7 @@
<dependency>
<groupId>org.springframework.data</groupId>
<artifactId>spring-data-bom</artifactId>
<version>${org.springframework.data.version}</version>
<version>${spring-data-bom.version}</version>
<scope>import</scope>
<type>pom</type>
</dependency>
Expand Down
28 changes: 6 additions & 22 deletions src/main/config/dependency-check-suppression.xml
Original file line number Diff line number Diff line change
@@ -1,29 +1,12 @@
<?xml version="1.0" encoding="UTF-8"?>

<!--
Copyright (c) 2021, 2023, Oracle and/or its affiliates.
Copyright (c) 2021, 2024, Oracle and/or its affiliates.
Licensed under the Universal Permissive License v 1.0 as shown at
https://oss.oracle.com/licenses/upl.
-->

<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
<suppress>
<notes><![CDATA[
file name: snakeyaml-1.33.jar
Not an issue.
See https://github.com/spring-projects/spring-boot/issues/33457
]]></notes>
<cve>CVE-2022-1471</cve>
</suppress>

<suppress>
<notes><![CDATA[
False positive: See https://github.com/jeremylong/DependencyCheck/issues/5912
]]></notes>
<packageUrl regex="true">^pkg:maven/io\.netty/@*.*$</packageUrl>
<vulnerabilityName>CVE-2023-4586</vulnerabilityName>
</suppress>

<suppress>
<notes><![CDATA[
Not applicable.
Expand All @@ -33,15 +16,16 @@

<suppress>
<notes><![CDATA[
Waiting for updated Spring / Spring Boot releases.
From grpc-core & grpc-protobuf 1.57.1
]]></notes>
<vulnerabilityName>CVE-2023-6378</vulnerabilityName>
<vulnerabilityName>CVE-2023-44487</vulnerabilityName>
</suppress>

<suppress>
<notes><![CDATA[
From grpc-core & grpc-protobuf 1.57.1
In Coherence Spring Cloud Config Demo
file name: sshd-osgi-2.10.0.jar
]]></notes>
<vulnerabilityName>CVE-2023-44487</vulnerabilityName>
<cve>CVE-2023-48795</cve>
</suppress>
</suppressions>

0 comments on commit fd66d51

Please sign in to comment.