Skip to content

Commit d22bb39

Browse files
author
Antoine Resenterra
committed
security(deps): fix vulnerabilities by upgrading java-common, nimbus, jersey, bcpkix, and logback
Upgraded multiple dependencies to patched versions to address known CVEs and keep the stack on maintained releases. - authlete-java-common: 4.19 → 4.21 - jersey.version: 2.30.1 → 2.34 - com.nimbusds:oauth2-oidc-sdk: 9.22 → 9.43.4 (removed jdk8 classifier) - org.bouncycastle:bcpkix-jdk18on: 1.78 → 1.78.1 - ch.qos.logback:logback-classic: 1.2.13 → 1.3.15
1 parent b4362f2 commit d22bb39

File tree

1 file changed

+5
-6
lines changed

1 file changed

+5
-6
lines changed

pom.xml

Lines changed: 5 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -12,11 +12,11 @@
1212
<properties>
1313
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
1414

15-
<authlete.java.common.version>4.19</authlete.java.common.version>
15+
<authlete.java.common.version>4.21</authlete.java.common.version>
1616
<authlete.java.jaxrs.version>2.86</authlete.java.jaxrs.version>
1717
<authlete.cbor.version>1.18</authlete.cbor.version>
1818
<javax.servlet-api.version>3.0.1</javax.servlet-api.version>
19-
<jersey.version>2.30.1</jersey.version>
19+
<jersey.version>2.34</jersey.version>
2020
<jetty.version>9.4.27.v20200227</jetty.version>
2121
<maven.compiler.plugin.version>3.10.1</maven.compiler.plugin.version>
2222
<maven.war.plugin.version>3.3.2</maven.war.plugin.version>
@@ -114,14 +114,13 @@
114114
<dependency>
115115
<groupId>org.bouncycastle</groupId>
116116
<artifactId>bcpkix-jdk18on</artifactId>
117-
<version>1.78</version>
117+
<version>1.78.1</version>
118118
</dependency>
119119

120120
<dependency>
121121
<groupId>com.nimbusds</groupId>
122122
<artifactId>oauth2-oidc-sdk</artifactId>
123-
<classifier>jdk8</classifier>
124-
<version>9.22</version>
123+
<version>9.43.4</version>
125124
</dependency>
126125

127126
<dependency>
@@ -133,7 +132,7 @@
133132
<dependency>
134133
<groupId>ch.qos.logback</groupId>
135134
<artifactId>logback-classic</artifactId>
136-
<version>1.2.13</version>
135+
<version>1.3.15</version>
137136
</dependency>
138137

139138
<dependency>

0 commit comments

Comments
 (0)