Skip to content

Commit 500bca5

Browse files
committed
Resolve more vulns in transitive dependencies
1 parent ecaaec3 commit 500bca5

File tree

1 file changed

+16
-2
lines changed

1 file changed

+16
-2
lines changed

build.gradle

Lines changed: 16 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -83,12 +83,26 @@ dependencies {
8383
implementation group: 'joda-time', name: 'joda-time', version: '2.14.0'
8484
implementation group: 'org.freemarker', name: 'freemarker', version: '2.3.34'
8585
constraints {
86-
implementation('commons-io:commons-io:2.19.0' ) {
86+
implementation('commons-io:commons-io:2.19.0') {
8787
because 'spotify docker-client uses an outdated version'
8888
}
89-
implementation('com.github.jnr:jnr-unixsocket:0.38.23' ) {
89+
implementation('org.apache.commons:commons-compress:1.27.1') {
9090
because 'spotify docker-client uses an outdated version'
9191
}
92+
implementation('org.apache.httpcomponents:httpclient:4.5.14') {
93+
because 'spotify docker-client uses an outdated version'
94+
}
95+
implementation('com.github.jnr:jnr-unixsocket:0.38.23') {
96+
because 'spotify docker-client uses an outdated version'
97+
}
98+
}
99+
modules {
100+
module('org.bouncycastle:bcpkix-jdk15on') {
101+
replacedBy('org.bouncycastle:bcpkix-jdk18on', "Everything can go via the JDK 1.8+ BouncyCastle version")
102+
}
103+
}
104+
implementation('org.bouncycastle:bcpkix-jdk18on:1.81') {
105+
because 'spotify docker-client uses an outdated version'
92106
}
93107
implementation(platform('com.fasterxml.jackson:jackson-bom:2.19.2')) // because 'spotify docker-client uses an outdated version'
94108

0 commit comments

Comments
 (0)