From 7bb8d31efa9558fd197ac40d66752f694a9edd9b Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 15 Jul 2024 04:51:21 +0000 Subject: [PATCH 1/2] fix: commons-packet/commons-packet-manager/pom.xml to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-COMHAZELCAST-1922239 - https://snyk.io/vuln/SNYK-JAVA-COMHAZELCAST-1018909 --- commons-packet/commons-packet-manager/pom.xml | 674 +++++++++--------- 1 file changed, 337 insertions(+), 337 deletions(-) diff --git a/commons-packet/commons-packet-manager/pom.xml b/commons-packet/commons-packet-manager/pom.xml index f56496f9eb..8a6525fe75 100644 --- a/commons-packet/commons-packet-manager/pom.xml +++ b/commons-packet/commons-packet-manager/pom.xml @@ -1,340 +1,340 @@ - + - - 4.0.0 - io.mosip.commons - commons-packet-manager - commons-packet-manager - Mosip commons project - https://github.com/mosip/commons - 1.2.1-java21-SNAPSHOT - - - UTF-8 - 21 - 21 - 3.8.0 - 3.0.2 - 3.1.0 - 3.2.0 - 2.3 - 2.8.1 - 2.2.1 - 1.5 - 1.6.7 - 3.0.1 - 2.22.0 - 1.2.1-java21-SNAPSHOT - 1.3.1 - - 1.2.1-java21-SNAPSHOT - 1.2.1-java21-SNAPSHOT - 1.2.1-java21-SNAPSHOT - 1.2.1-java21-SNAPSHOT - 1.2.1-java21-SNAPSHOT - 1.2.1-java21-SNAPSHOT - 1.2.1-java21-SNAPSHOT - 1.2.1-java21-SNAPSHOT - 1.2.1-java21-SNAPSHOT - 1.2.1-java21-SNAPSHOT - 1.2.1-java21-SNAPSHOT - 3.11.2 - **/constants/**,**/config/**,**/audit/**,**/util/**,**/dto/**,**/entity/**,**/model/**,**/exception/**,**/repository/**,**/security/**,**/*Config.java,**/*BootApplication.java,**/*VertxApplication.java,**/cbeffutil/**,**/*Utils.java,**/*Validator.java,**/*Helper.java,**/verticle/**,**/VidWriter.java/**,**/masterdata/utils/**,**/spi/**,**/core/http/**,"**/LocationServiceImpl.java","**/RegistrationCenterMachineServiceImpl.java","**/RegistrationCenterServiceImpl.java","**/pridgenerator/**","**/idgenerator/prid","**/proxy/**","**/cryptosignature/**" - **/dto/**,**/entity/**,**/config/** - 0.8.11 - - - - - - io.mosip.kernel - kernel-bom - ${kernel.bom.version} - pom - import - - - - - - io.mosip.kernel - kernel-idobjectvalidator - ${kernel-idobjectvalidator.version} - - - org.springframework.boot - spring-boot-starter-security - - - io.mosip.kernel - kernel-core - ${kernel.core.version} - - - com.hazelcast - hazelcast-kubernetes - ${hazelcast.kubernetes.version} - - - com.googlecode.json-simple - json-simple - - - io.mosip.kernel - kernel-logger-logback - ${kernel.logger.logback.version} - - - io.mosip.kernel - kernel-cbeffutil-api - ${kernel.cbeffutil.api.version} - - - io.mosip.kernel - kernel-biometrics-api - ${kernel.biometrics.api.version} - - - org.springframework.boot - spring-boot-starter-cache - - - io.mosip.commons - khazana - ${khazana.version} - - - org.powermock - powermock-module-junit4 - test - - - org.powermock - powermock-api-mockito2 - test - - - jakarta.xml.bind - jakarta.xml.bind-api - - - io.mosip.kernel - kernel-keymanager-service - ${kernel-keymanager-service.version} - - - org.springframework.security - spring-security-config - - - lib - - - junit - junit - test - - - org.apache.commons - commons-collections4 - - - org.junit.vintage - junit-vintage-engine - - - org.mockito - mockito-core - ${mockito.core.version} - - - - - - - ossrh - https://oss.sonatype.org/content/repositories/snapshots - - - ossrh - https://oss.sonatype.org/service/local/staging/deploy/maven2/ - - - - - - org.apache.maven.plugins - maven-surefire-plugin - ${maven.surefire.plugin.version} - - false - false - - --add-opens java.xml/jdk.xml.internal=ALL-UNNAMED --add-opens java.base/java.lang=ALL-UNNAMED --add-opens java.base/java.util=ALL-UNNAMED --add-opens java.base/java.io=ALL-UNNAMED --enable-preview - - - - - org.apache.maven.plugins - maven-compiler-plugin - - ${maven.compiler.source} - ${maven.compiler.target} - - - - - maven-deploy-plugin - ${maven.deploy.plugin.version} - - - default-deploy - deploy - - deploy - - - - - - org.sonatype.plugins - nexus-staging-maven-plugin - ${nexus.staging.plugin.version} - true - - - default-deploy - deploy - - deploy - - - - - ossrh - https://oss.sonatype.org/ - false - - - - - org.apache.maven.plugins - maven-source-plugin - true - ${maven.source.plugin.version} - - - attach-sources - - jar-no-fork - - - - - - - org.apache.maven.plugins - maven-javadoc-plugin - ${maven.javadoc.version} - - - attach-javadocs - - jar - - - - - none - - - - org.apache.maven.plugins - maven-gpg-plugin - ${maven.gpg.plugin.version} - - - sign-artifacts - verify - - sign - - - - --pinentry-mode - loopback - - - - - - - - org.jacoco - jacoco-maven-plugin - ${jacoco.maven.plugin.version} - - - - prepare-agent - - - - report - prepare-package - - report - - - - - - pl.project13.maven - git-commit-id-plugin - ${git.commit.plugin.version} - - - get-the-git-infos - - revision - - validate - - - - true - ${project.build.outputDirectory}/git.properties - - ^git.build.(time|version)$ - ^git.commit.id.(abbrev|full)$ - - full - ${project.basedir}/.git - - - - - - - scm:git:git://github.com/mosip/packet-manager.git - scm:git:ssh://github.com:mosip/packet-manager.git - https://github.com/mosip/commons - HEAD - - - - MPL 2.0 - https://www.mozilla.org/en-US/MPL/2.0/ - - - - - Mosip - mosip.emailnotifier@gmail.com - io.mosip - https://github.com/mosip/commons - - + xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd"> + + 4.0.0 + io.mosip.commons + commons-packet-manager + commons-packet-manager + Mosip commons project + https://github.com/mosip/commons + 1.2.1-java21-SNAPSHOT + + + UTF-8 + 21 + 21 + 3.8.0 + 3.0.2 + 3.1.0 + 3.2.0 + 2.3 + 2.8.1 + 2.2.1 + 1.5 + 1.6.7 + 3.0.1 + 2.22.0 + 1.2.1-java21-SNAPSHOT + 2.2.1 + + 1.2.1-java21-SNAPSHOT + 1.2.1-java21-SNAPSHOT + 1.2.1-java21-SNAPSHOT + 1.2.1-java21-SNAPSHOT + 1.2.1-java21-SNAPSHOT + 1.2.1-java21-SNAPSHOT + 1.2.1-java21-SNAPSHOT + 1.2.1-java21-SNAPSHOT + 1.2.1-java21-SNAPSHOT + 1.2.1-java21-SNAPSHOT + 1.2.1-java21-SNAPSHOT + 3.11.2 + **/constants/**,**/config/**,**/audit/**,**/util/**,**/dto/**,**/entity/**,**/model/**,**/exception/**,**/repository/**,**/security/**,**/*Config.java,**/*BootApplication.java,**/*VertxApplication.java,**/cbeffutil/**,**/*Utils.java,**/*Validator.java,**/*Helper.java,**/verticle/**,**/VidWriter.java/**,**/masterdata/utils/**,**/spi/**,**/core/http/**,"**/LocationServiceImpl.java","**/RegistrationCenterMachineServiceImpl.java","**/RegistrationCenterServiceImpl.java","**/pridgenerator/**","**/idgenerator/prid","**/proxy/**","**/cryptosignature/**" + **/dto/**,**/entity/**,**/config/** + 0.8.11 + + + + + + io.mosip.kernel + kernel-bom + ${kernel.bom.version} + pom + import + + + + + + io.mosip.kernel + kernel-idobjectvalidator + ${kernel-idobjectvalidator.version} + + + org.springframework.boot + spring-boot-starter-security + + + io.mosip.kernel + kernel-core + ${kernel.core.version} + + + com.hazelcast + hazelcast-kubernetes + ${hazelcast.kubernetes.version} + + + com.googlecode.json-simple + json-simple + + + io.mosip.kernel + kernel-logger-logback + ${kernel.logger.logback.version} + + + io.mosip.kernel + kernel-cbeffutil-api + ${kernel.cbeffutil.api.version} + + + io.mosip.kernel + kernel-biometrics-api + ${kernel.biometrics.api.version} + + + org.springframework.boot + spring-boot-starter-cache + + + io.mosip.commons + khazana + ${khazana.version} + + + org.powermock + powermock-module-junit4 + test + + + org.powermock + powermock-api-mockito2 + test + + + jakarta.xml.bind + jakarta.xml.bind-api + + + io.mosip.kernel + kernel-keymanager-service + ${kernel-keymanager-service.version} + + + org.springframework.security + spring-security-config + + + lib + + + junit + junit + test + + + org.apache.commons + commons-collections4 + + + org.junit.vintage + junit-vintage-engine + + + org.mockito + mockito-core + ${mockito.core.version} + + + + + + + ossrh + https://oss.sonatype.org/content/repositories/snapshots + + + ossrh + https://oss.sonatype.org/service/local/staging/deploy/maven2/ + + + + + + org.apache.maven.plugins + maven-surefire-plugin + ${maven.surefire.plugin.version} + + false + false + + --add-opens java.xml/jdk.xml.internal=ALL-UNNAMED --add-opens java.base/java.lang=ALL-UNNAMED --add-opens java.base/java.util=ALL-UNNAMED --add-opens java.base/java.io=ALL-UNNAMED --enable-preview + + + + + org.apache.maven.plugins + maven-compiler-plugin + + ${maven.compiler.source} + ${maven.compiler.target} + + + + + maven-deploy-plugin + ${maven.deploy.plugin.version} + + + default-deploy + deploy + + deploy + + + + + + org.sonatype.plugins + nexus-staging-maven-plugin + ${nexus.staging.plugin.version} + true + + + default-deploy + deploy + + deploy + + + + + ossrh + https://oss.sonatype.org/ + false + + + + + org.apache.maven.plugins + maven-source-plugin + true + ${maven.source.plugin.version} + + + attach-sources + + jar-no-fork + + + + + + + org.apache.maven.plugins + maven-javadoc-plugin + ${maven.javadoc.version} + + + attach-javadocs + + jar + + + + + none + + + + org.apache.maven.plugins + maven-gpg-plugin + ${maven.gpg.plugin.version} + + + sign-artifacts + verify + + sign + + + + --pinentry-mode + loopback + + + + + + + + org.jacoco + jacoco-maven-plugin + ${jacoco.maven.plugin.version} + + + + prepare-agent + + + + report + prepare-package + + report + + + + + + pl.project13.maven + git-commit-id-plugin + ${git.commit.plugin.version} + + + get-the-git-infos + + revision + + validate + + + + true + ${project.build.outputDirectory}/git.properties + + ^git.build.(time|version)$ + ^git.commit.id.(abbrev|full)$ + + full + ${project.basedir}/.git + + + + + + + scm:git:git://github.com/mosip/packet-manager.git + scm:git:ssh://github.com:mosip/packet-manager.git + https://github.com/mosip/commons + HEAD + + + + MPL 2.0 + https://www.mozilla.org/en-US/MPL/2.0/ + + + + + Mosip + mosip.emailnotifier@gmail.com + io.mosip + https://github.com/mosip/commons + + From 2c759dddf85f2b9065cb607cc82b273bfc81ee64 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 15 Jul 2024 04:52:14 +0000 Subject: [PATCH 2/2] fix: commons-packet/commons-packet-service/pom.xml to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-IOSPRINGFOX-1075064 - https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-32236 - https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-1015415 - https://snyk.io/vuln/SNYK-JAVA-COMGOOGLEGUAVA-5710356 --- commons-packet/commons-packet-service/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/commons-packet/commons-packet-service/pom.xml b/commons-packet/commons-packet-service/pom.xml index 9b60b03e47..2f444f8090 100644 --- a/commons-packet/commons-packet-service/pom.xml +++ b/commons-packet/commons-packet-service/pom.xml @@ -28,7 +28,7 @@ 1.2.1-java21-SNAPSHOT - 2.9.2 + 2.10.0 1.2.1-java21-SNAPSHOT 1.2.1-java21-SNAPSHOT