From 4345058ccbd3a4f20a366157e2a1d7ad17a84562 Mon Sep 17 00:00:00 2001 From: Denis Yuen Date: Wed, 10 Mar 2021 11:33:15 -0500 Subject: [PATCH] Address CVE https://github.com/dockstore/dockstore/security/dependabot/bom-internal/pom.xml/org.eclipse.jetty:jetty-server/open but might also run into pgp issue --- THIRD-PARTY-LICENSES.txt | 94 ++++++++++++++++++++-------------------- bom-internal/pom.xml | 12 ++--- 2 files changed, 53 insertions(+), 53 deletions(-) diff --git a/THIRD-PARTY-LICENSES.txt b/THIRD-PARTY-LICENSES.txt index 17d7c9c4e3..6ffd7f46d0 100644 --- a/THIRD-PARTY-LICENSES.txt +++ b/THIRD-PARTY-LICENSES.txt @@ -6,7 +6,7 @@ Lists of 370 third-party dependencies. (Apache License, Version 2.0) akka-stream (com.typesafe.akka:akka-stream_2.12:2.5.31 - https://akka.io/) (MIT) Alleycats core (org.typelevel:alleycats-core_2.12:2.3.0 - https://github.com/typelevel/cats) (Apache 2.0) annotation (org.typelevel:simulacrum-scalafix-annotations_2.12:0.5.4 - https://github.com/typelevel/simulacrum-scalafix) - (Apache License 2.0) Annotations for Metrics (io.dropwizard.metrics:metrics-annotation:4.1.17 - https://metrics.dropwizard.io/metrics-annotation) + (Apache License 2.0) Annotations for Metrics (io.dropwizard.metrics:metrics-annotation:4.1.18 - https://metrics.dropwizard.io/metrics-annotation) (The BSD License) ANTLR 4 Runtime (org.antlr:antlr4-runtime:4.7.2 - http://www.antlr.org/antlr4-runtime) (BSD License) AntLR Parser Generator (antlr:antlr:2.7.7 - http://www.antlr.org/) (EPL 2.0) (GPL2 w/ CPE) aopalliance version 1.0 repackaged as a module (org.glassfish.hk2.external:aopalliance-repackaged:2.6.1 - https://github.com/eclipse-ee4j/glassfish-hk2/external/aopalliance-repackaged) @@ -75,7 +75,7 @@ Lists of 370 third-party dependencies. (Bouncy Castle Licence) Bouncy Castle Provider (org.bouncycastle:bcprov-ext-jdk15on:1.54 - http://www.bouncycastle.org/java.html) (Apache License, Version 2.0) Byte Buddy (without dependencies) (net.bytebuddy:byte-buddy:1.10.10 - https://bytebuddy.net/byte-buddy) (Apache License, Version 2.0) Byte Buddy agent (net.bytebuddy:byte-buddy-agent:1.10.10 - https://bytebuddy.net/byte-buddy-agent) - (Apache License, Version 2.0) Caffeine cache (com.github.ben-manes.caffeine:caffeine:2.8.8 - https://github.com/ben-manes/caffeine) + (Apache License, Version 2.0) Caffeine cache (com.github.ben-manes.caffeine:caffeine:2.9.0 - https://github.com/ben-manes/caffeine) (Apache 2.0) cats (com.softwaremill.sttp:cats_2.12:1.5.19 - http://softwaremill.com/open-source) (MIT) Cats core (org.typelevel:cats-core_2.12:2.4.2 - https://github.com/typelevel/cats) (MIT) Cats kernel (org.typelevel:cats-kernel_2.12:2.4.2 - https://github.com/typelevel/cats) @@ -120,27 +120,27 @@ Lists of 370 third-party dependencies. (Apache License, Version 2.0) cwlavro-tools (io.cwl:cwlavro-tools:2.0.4.4 - no url defined) (The Apache Software License, Version 2.0) docker-client (com.spotify:docker-client:8.16.0 - https://github.com/spotify/docker-client) (https://github.com/dom4j/dom4j/blob/master/LICENSE) dom4j (dom4j:dom4j:1.6.1 - http://dom4j.org) - (Apache License 2.0) Dropwizard (io.dropwizard:dropwizard-core:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-core) - (Apache License 2.0) Dropwizard Asset Bundle (io.dropwizard:dropwizard-assets:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-assets) - (Apache License 2.0) Dropwizard Authentication (io.dropwizard:dropwizard-auth:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-auth) - (Apache License 2.0) Dropwizard Configuration Support (io.dropwizard:dropwizard-configuration:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-configuration) - (Apache License 2.0) Dropwizard Database Support (io.dropwizard:dropwizard-db:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-db) - (Apache License 2.0) Dropwizard Hibernate Support (io.dropwizard:dropwizard-hibernate:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-hibernate) - (Apache License 2.0) Dropwizard HTTP Client (io.dropwizard:dropwizard-client:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-client) - (Apache License 2.0) Dropwizard Jackson Support (io.dropwizard:dropwizard-jackson:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-jackson) - (Apache License 2.0) Dropwizard JDBI3 Support (io.dropwizard:dropwizard-jdbi3:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-jdbi3) - (Apache License 2.0) Dropwizard Jersey Support (io.dropwizard:dropwizard-jersey:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-jersey) - (Apache License 2.0) Dropwizard Jetty Support (io.dropwizard:dropwizard-jetty:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-jetty) - (Apache License 2.0) Dropwizard Lifecycle Support (io.dropwizard:dropwizard-lifecycle:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-lifecycle) - (Apache License 2.0) Dropwizard Logging Support (io.dropwizard:dropwizard-logging:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-logging) - (Apache License 2.0) Dropwizard Metrics Support (io.dropwizard:dropwizard-metrics:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-metrics) - (Apache License 2.0) Dropwizard Migrations (io.dropwizard:dropwizard-migrations:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-migrations) - (Apache License 2.0) Dropwizard Multipart Form Support (io.dropwizard:dropwizard-forms:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-forms) - (Apache License 2.0) Dropwizard Request Logging Support (io.dropwizard:dropwizard-request-logging:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-request-logging) - (Apache License 2.0) Dropwizard Servlet Support (io.dropwizard:dropwizard-servlets:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-servlets) - (Apache License 2.0) Dropwizard Test Helpers (io.dropwizard:dropwizard-testing:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-testing) - (Apache License 2.0) Dropwizard Utility Classes (io.dropwizard:dropwizard-util:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-util) - (Apache License 2.0) Dropwizard Validation Support (io.dropwizard:dropwizard-validation:2.0.19 - http://www.dropwizard.io/2.0.19/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-validation) + (Apache License 2.0) Dropwizard (io.dropwizard:dropwizard-core:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-core) + (Apache License 2.0) Dropwizard Asset Bundle (io.dropwizard:dropwizard-assets:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-assets) + (Apache License 2.0) Dropwizard Authentication (io.dropwizard:dropwizard-auth:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-auth) + (Apache License 2.0) Dropwizard Configuration Support (io.dropwizard:dropwizard-configuration:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-configuration) + (Apache License 2.0) Dropwizard Database Support (io.dropwizard:dropwizard-db:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-db) + (Apache License 2.0) Dropwizard Hibernate Support (io.dropwizard:dropwizard-hibernate:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-hibernate) + (Apache License 2.0) Dropwizard HTTP Client (io.dropwizard:dropwizard-client:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-client) + (Apache License 2.0) Dropwizard Jackson Support (io.dropwizard:dropwizard-jackson:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-jackson) + (Apache License 2.0) Dropwizard JDBI3 Support (io.dropwizard:dropwizard-jdbi3:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-jdbi3) + (Apache License 2.0) Dropwizard Jersey Support (io.dropwizard:dropwizard-jersey:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-jersey) + (Apache License 2.0) Dropwizard Jetty Support (io.dropwizard:dropwizard-jetty:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-jetty) + (Apache License 2.0) Dropwizard Lifecycle Support (io.dropwizard:dropwizard-lifecycle:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-lifecycle) + (Apache License 2.0) Dropwizard Logging Support (io.dropwizard:dropwizard-logging:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-logging) + (Apache License 2.0) Dropwizard Metrics Support (io.dropwizard:dropwizard-metrics:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-metrics) + (Apache License 2.0) Dropwizard Migrations (io.dropwizard:dropwizard-migrations:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-migrations) + (Apache License 2.0) Dropwizard Multipart Form Support (io.dropwizard:dropwizard-forms:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-forms) + (Apache License 2.0) Dropwizard Request Logging Support (io.dropwizard:dropwizard-request-logging:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-request-logging) + (Apache License 2.0) Dropwizard Servlet Support (io.dropwizard:dropwizard-servlets:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-servlets) + (Apache License 2.0) Dropwizard Test Helpers (io.dropwizard:dropwizard-testing:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-testing) + (Apache License 2.0) Dropwizard Utility Classes (io.dropwizard:dropwizard-util:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-util) + (Apache License 2.0) Dropwizard Validation Support (io.dropwizard:dropwizard-validation:2.0.20 - http://www.dropwizard.io/2.0.20/dropwizard-bom/dropwizard-dependencies/dropwizard-parent/dropwizard-validation) (Apache 2) EasyMock (org.easymock:easymock:4.0.1 - http://easymock.org/easymock) (The Apache Software License, Version 2.0) elasticsearch-core (org.elasticsearch:elasticsearch-core:7.10.0 - https://github.com/elastic/elasticsearch) (The Apache Software License, Version 2.0) elasticsearch-x-content (org.elasticsearch:elasticsearch-x-content:7.10.0 - https://github.com/elastic/elasticsearch) @@ -184,7 +184,7 @@ Lists of 370 third-party dependencies. (The Apache Software License, Version 2.0) Jackson datatype: Joda (com.fasterxml.jackson.datatype:jackson-datatype-joda:2.12.1 - https://github.com/FasterXML/jackson-datatype-joda) (The Apache Software License, Version 2.0) Jackson datatype: JSR310 (com.fasterxml.jackson.datatype:jackson-datatype-jsr310:2.12.1 - https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310) (The Apache Software License, Version 2.0) Jackson extensions to the Google HTTP Client Library for Java. (com.google.http-client:google-http-client-jackson:1.29.2 - https://github.com/googleapis/google-http-java-client/google-http-client-jackson) - (Apache License 2.0) Jackson Integration for Metrics (io.dropwizard.metrics:metrics-json:4.1.17 - https://metrics.dropwizard.io/metrics-json) + (Apache License 2.0) Jackson Integration for Metrics (io.dropwizard.metrics:metrics-json:4.1.18 - https://metrics.dropwizard.io/metrics-json) (The Apache Software License, Version 2.0) Jackson module: Afterburner (com.fasterxml.jackson.module:jackson-module-afterburner:2.12.1 - https://github.com/FasterXML/jackson-modules-base) (The Apache Software License, Version 2.0) Jackson module: JAXB Annotations (com.fasterxml.jackson.module:jackson-module-jaxb-annotations:2.12.1 - https://github.com/FasterXML/jackson-modules-base) (The Apache Software License, Version 2.0) Jackson-annotations (com.fasterxml.jackson.core:jackson-annotations:2.12.1 - http://github.com/FasterXML/jackson) @@ -246,16 +246,16 @@ Lists of 370 third-party dependencies. (Apache License, 2.0) (BSD 2-Clause) (EDL 1.0) (EPL 2.0) (GPL2 w/ CPE) (MIT license) (Modified BSD) (Public Domain) (W3C license) (jQuery license) jersey-media-multipart (org.glassfish.jersey.media:jersey-media-multipart:2.33 - https://projects.eclipse.org/projects/ee4j.jersey/project/jersey-media-multipart) (Apache License, 2.0) (BSD 2-Clause) (EDL 1.0) (EPL 2.0) (GPL2 w/ CPE) (MIT license) (Modified BSD) (Public Domain) (W3C license) (jQuery license) jersey-test-framework-core (org.glassfish.jersey.test-framework:jersey-test-framework-core:2.33 - https://projects.eclipse.org/projects/ee4j.jersey/project/jersey-test-framework-core) (Apache License, 2.0) (BSD 2-Clause) (EDL 1.0) (EPL 2.0) (GPL2 w/ CPE) (MIT license) (Modified BSD) (Public Domain) (W3C license) (jQuery license) jersey-test-framework-provider-inmemory (org.glassfish.jersey.test-framework.providers:jersey-test-framework-provider-inmemory:2.33 - https://projects.eclipse.org/projects/ee4j.jersey/project/project/jersey-test-framework-provider-inmemory) - (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: Continuation (org.eclipse.jetty:jetty-continuation:9.4.36.v20210114 - https://eclipse.org/jetty/jetty-continuation) - (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: Http Utility (org.eclipse.jetty:jetty-http:9.4.36.v20210114 - https://eclipse.org/jetty/jetty-http) - (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: IO Utility (org.eclipse.jetty:jetty-io:9.4.36.v20210114 - https://eclipse.org/jetty/jetty-io) - (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: Security (org.eclipse.jetty:jetty-security:9.4.36.v20210114 - https://eclipse.org/jetty/jetty-security) - (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: Server Core (org.eclipse.jetty:jetty-server:9.4.36.v20210114 - https://eclipse.org/jetty/jetty-server) - (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: Servlet Handling (org.eclipse.jetty:jetty-servlet:9.4.36.v20210114 - https://eclipse.org/jetty/jetty-servlet) + (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: Continuation (org.eclipse.jetty:jetty-continuation:9.4.37.v20210219 - https://eclipse.org/jetty/jetty-continuation) + (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: Http Utility (org.eclipse.jetty:jetty-http:9.4.37.v20210219 - https://eclipse.org/jetty/jetty-http) + (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: IO Utility (org.eclipse.jetty:jetty-io:9.4.37.v20210219 - https://eclipse.org/jetty/jetty-io) + (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: Security (org.eclipse.jetty:jetty-security:9.4.37.v20210219 - https://eclipse.org/jetty/jetty-security) + (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: Server Core (org.eclipse.jetty:jetty-server:9.4.37.v20210219 - https://eclipse.org/jetty/jetty-server) + (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: Servlet Handling (org.eclipse.jetty:jetty-servlet:9.4.37.v20210219 - https://eclipse.org/jetty/jetty-servlet) (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: SetUID Java (org.eclipse.jetty.toolchain.setuid:jetty-setuid-java:1.0.4 - https://eclipse.org/jetty/jetty-setuid-parent/jetty-setuid-java) - (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: Utilities (org.eclipse.jetty:jetty-util:9.4.36.v20210114 - https://eclipse.org/jetty/jetty-util) - (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: Utilities :: Ajax(JSON) (org.eclipse.jetty:jetty-util-ajax:9.4.36.v20210114 - https://eclipse.org/jetty/jetty-util-ajax) - (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: Utility Servlets and Filters (org.eclipse.jetty:jetty-servlets:9.4.36.v20210114 - https://eclipse.org/jetty/jetty-servlets) + (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: Utilities (org.eclipse.jetty:jetty-util:9.4.37.v20210219 - https://eclipse.org/jetty/jetty-util) + (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: Utilities :: Ajax(JSON) (org.eclipse.jetty:jetty-util-ajax:9.4.37.v20210219 - https://eclipse.org/jetty/jetty-util-ajax) + (Apache Software License - Version 2.0) (Eclipse Public License - Version 1.0) Jetty :: Utility Servlets and Filters (org.eclipse.jetty:jetty-servlets:9.4.37.v20210219 - https://eclipse.org/jetty/jetty-servlets) (The Apache Software License, Version 2.0) jffi (com.github.jnr:jffi:1.2.15 - http://github.com/jnr/jffi) (Apache License, Version 2.0) JMES Path Query library (com.amazonaws:jmespath-java:1.11.505 - https://aws.amazon.com/sdkforjava) (The Apache Software License, Version 2.0) jnr-constants (com.github.jnr:jnr-constants:0.9.8 - http://github.com/jnr/jnr-constants) @@ -264,13 +264,13 @@ Lists of 370 third-party dependencies. (Common Public License - v 1.0) (GNU General Public License Version 2) (GNU Lesser General Public License Version 2.1) jnr-posix (com.github.jnr:jnr-posix:3.0.35 - http://nexus.sonatype.org/oss-repository-hosting.html/jnr-posix) (The Apache Software License, Version 2.0) jnr-unixsocket (com.github.jnr:jnr-unixsocket:0.18 - http://github.com/jnr/jnr-unixsocket) (MIT License) jnr-x86asm (com.github.jnr:jnr-x86asm:1.0.2 - http://github.com/jnr/jnr-x86asm) - (Apache License, Version 2.0) Joda-Time (joda-time:joda-time:2.10.9 - https://www.joda.org/joda-time/) + (Apache License, Version 2.0) Joda-Time (joda-time:joda-time:2.10.10 - https://www.joda.org/joda-time/) (The JSON License) JSON in Java (org.json:json:20180130 - https://github.com/douglascrockford/JSON-java) (The Apache Software License, Version 2.0) JSON.simple (com.googlecode.json-simple:json-simple:1.1.1 - http://code.google.com/p/json-simple/) (Revised BSD License) JSONLD Java :: Core (com.github.jsonld-java:jsonld-java:0.8.3 - http://github.com/jsonld-java/jsonld-java/jsonld-java/) (MIT License) JUL to SLF4J bridge (org.slf4j:jul-to-slf4j:1.7.30 - http://www.slf4j.org) (Eclipse Public License 1.0) JUnit (junit:junit:4.13.1 - http://junit.org) - (Apache License 2.0) JVM Integration for Metrics (io.dropwizard.metrics:metrics-jvm:4.1.17 - https://metrics.dropwizard.io/metrics-jvm) + (Apache License 2.0) JVM Integration for Metrics (io.dropwizard.metrics:metrics-jvm:4.1.18 - https://metrics.dropwizard.io/metrics-jvm) (The Apache Software License, Version 2.0) lang-mustache (org.elasticsearch.plugin:lang-mustache-client:7.10.0 - https://github.com/elastic/elasticsearch) (WDL License https://github.com/openwdl/wdl/blob/master/LICENSE) language-factory-core (org.broadinstitute:language-factory-core_2.12:57 - no url defined) (Apache License, Version 2.0) Liquibase (org.liquibase:liquibase-core:3.10.2 - http://www.liquibase.org/liquibase-root/liquibase-dist) @@ -282,16 +282,16 @@ Lists of 370 third-party dependencies. (Eclipse Public License - v 1.0) (GNU Lesser General Public License) Logback Core Module (ch.qos.logback:logback-core:1.2.3 - http://logback.qos.ch/logback-core) (Apache License, Version 2.0) (MIT License) Logstash Logback Encoder (net.logstash.logback:logstash-logback-encoder:4.11 - https://github.com/logstash/logstash-logback-encoder) (Apache License, Version 2.0) Lucene Core (org.apache.lucene:lucene-core:8.7.0 - https://lucene.apache.org/lucene-parent/lucene-core) - (Apache License 2.0) Metrics Core (io.dropwizard.metrics:metrics-core:4.1.17 - https://metrics.dropwizard.io/metrics-core) - (Apache License 2.0) Metrics Health Checks (io.dropwizard.metrics:metrics-healthchecks:4.1.17 - https://metrics.dropwizard.io/metrics-healthchecks) - (Apache License 2.0) Metrics Integration for Apache HttpClient (io.dropwizard.metrics:metrics-httpclient:4.1.17 - https://metrics.dropwizard.io/metrics-httpclient) - (Apache License 2.0) Metrics Integration for Caffeine (io.dropwizard.metrics:metrics-caffeine:4.1.17 - https://metrics.dropwizard.io/metrics-caffeine) - (Apache License 2.0) Metrics Integration for JDBI3 (io.dropwizard.metrics:metrics-jdbi3:4.1.17 - https://metrics.dropwizard.io/metrics-jdbi3) - (Apache License 2.0) Metrics Integration for Jersey 2.x (io.dropwizard.metrics:metrics-jersey2:4.1.17 - https://metrics.dropwizard.io/metrics-jersey2) - (Apache License 2.0) Metrics Integration for Jetty 9.3 and higher (io.dropwizard.metrics:metrics-jetty9:4.1.17 - https://metrics.dropwizard.io/metrics-jetty9) - (Apache License 2.0) Metrics Integration for Logback (io.dropwizard.metrics:metrics-logback:4.1.17 - https://metrics.dropwizard.io/metrics-logback) - (Apache License 2.0) Metrics Integration with JMX (io.dropwizard.metrics:metrics-jmx:4.1.17 - https://metrics.dropwizard.io/metrics-jmx) - (Apache License 2.0) Metrics Utility Servlets (io.dropwizard.metrics:metrics-servlets:4.1.17 - https://metrics.dropwizard.io/metrics-servlets) + (Apache License 2.0) Metrics Core (io.dropwizard.metrics:metrics-core:4.1.18 - https://metrics.dropwizard.io/metrics-core) + (Apache License 2.0) Metrics Health Checks (io.dropwizard.metrics:metrics-healthchecks:4.1.18 - https://metrics.dropwizard.io/metrics-healthchecks) + (Apache License 2.0) Metrics Integration for Apache HttpClient (io.dropwizard.metrics:metrics-httpclient:4.1.18 - https://metrics.dropwizard.io/metrics-httpclient) + (Apache License 2.0) Metrics Integration for Caffeine (io.dropwizard.metrics:metrics-caffeine:4.1.18 - https://metrics.dropwizard.io/metrics-caffeine) + (Apache License 2.0) Metrics Integration for JDBI3 (io.dropwizard.metrics:metrics-jdbi3:4.1.18 - https://metrics.dropwizard.io/metrics-jdbi3) + (Apache License 2.0) Metrics Integration for Jersey 2.x (io.dropwizard.metrics:metrics-jersey2:4.1.18 - https://metrics.dropwizard.io/metrics-jersey2) + (Apache License 2.0) Metrics Integration for Jetty 9.3 and higher (io.dropwizard.metrics:metrics-jetty9:4.1.18 - https://metrics.dropwizard.io/metrics-jetty9) + (Apache License 2.0) Metrics Integration for Logback (io.dropwizard.metrics:metrics-logback:4.1.18 - https://metrics.dropwizard.io/metrics-logback) + (Apache License 2.0) Metrics Integration with JMX (io.dropwizard.metrics:metrics-jmx:4.1.18 - https://metrics.dropwizard.io/metrics-jmx) + (Apache License 2.0) Metrics Utility Servlets (io.dropwizard.metrics:metrics-servlets:4.1.18 - https://metrics.dropwizard.io/metrics-servlets) (Apache 2) metrics-scala (nl.grons:metrics-scala_2.12:4.0.0 - https://github.com/erikvanoosten/metrics-scala) (WDL License https://github.com/openwdl/wdl/blob/master/LICENSE) metrics-statsd-common (com.readytalk:metrics-statsd-common:4.2.0 - no url defined) (The Apache Software License, Version 2.0) metrics3-statsd (com.readytalk:metrics3-statsd:4.2.0 - no url defined) @@ -362,8 +362,8 @@ Lists of 370 third-party dependencies. (Apache License 2.0) swagger-models (io.swagger:swagger-models:1.6.2 - https://github.com/swagger-api/swagger-core/modules/swagger-models) (Common Public License Version 1.0) System Rules (com.github.stefanbirkner:system-rules:1.19.0 - http://stefanbirkner.github.io/system-rules/) (Apache License 2.0) Throttling Appender (io.dropwizard.logback:logback-throttling-appender:1.1.0 - https://github.com/dropwizard/logback-throttling-appender/) - (Apache License, Version 2.0) tomcat-jdbc (org.apache.tomcat:tomcat-jdbc:9.0.41 - https://tomcat.apache.org/) - (Apache License, Version 2.0) tomcat-juli (org.apache.tomcat:tomcat-juli:9.0.41 - https://tomcat.apache.org/) + (Apache License, Version 2.0) tomcat-jdbc (org.apache.tomcat:tomcat-jdbc:9.0.43 - https://tomcat.apache.org/) + (Apache License, Version 2.0) tomcat-juli (org.apache.tomcat:tomcat-juli:9.0.43 - https://tomcat.apache.org/) (Eclipse Distribution License - v 1.0) TXW2 Runtime (org.glassfish.jaxb:txw2:2.3.3 - https://eclipse-ee4j.github.io/jaxb-ri/jaxb-txw-parent/txw2) (WDL License https://github.com/openwdl/wdl/blob/master/LICENSE) wdl-biscayne (org.broadinstitute:wdl-biscayne_2.12:57 - no url defined) (WDL License https://github.com/openwdl/wdl/blob/master/LICENSE) wdl-draft2 (org.broadinstitute:wdl-draft2_2.12:57 - no url defined) diff --git a/bom-internal/pom.xml b/bom-internal/pom.xml index f51d28afe3..ce8d42270d 100644 --- a/bom-internal/pom.xml +++ b/bom-internal/pom.xml @@ -46,8 +46,8 @@ POM as their parent. UTF-8 UTF-8 - 2.0.19 - 4.1.17 + 2.0.20 + 4.1.18 7.10.0 1.6.2 2.1.1 @@ -65,7 +65,7 @@ POM as their parent. 3.25.0 4.5.13 4.4.14 - 9.4.36.v20210114 + 9.4.37.v20210219 4.1.60.Final 2.12.13 57 @@ -343,7 +343,7 @@ POM as their parent. joda-time joda-time - 2.10.9 + 2.10.10 @@ -416,7 +416,7 @@ POM as their parent. org.checkerframework checker-qual - 3.8.0 + 3.10.0 jakarta.annotation @@ -953,7 +953,7 @@ POM as their parent. com.github.ben-manes.caffeine caffeine - 2.8.8 + 2.9.0