Skip to content

Commit ffe45fa

Browse files
committed
Update dependency versions to align with the spring boot 4.0.x upgrade
1 parent 76029fb commit ffe45fa

1 file changed

Lines changed: 19 additions & 11 deletions

File tree

build-parent/pom.xml

Lines changed: 19 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -51,28 +51,29 @@
5151
- A version property must be specified in the format "version.{groupId}", optionally with a suffix to make it unique.
5252
- Version properties must be sorted alphabetically (other form of sorting were found to be unclear and ambiguous).
5353
-->
54-
<version.ch.qos.logback>1.5.25</version.ch.qos.logback>
54+
<version.ch.qos.logback>1.5.32</version.ch.qos.logback>
5555
<version.commons-codec>1.19.0</version.commons-codec>
5656
<version.commons-collections>3.2.2</version.commons-collections>
5757
<version.commons-logging>1.1.1</version.commons-logging>
5858
<version.commons-io>2.20.0</version.commons-io>
5959
<version.common-text>1.14.0</version.common-text>
60-
<version.com.fasterxml.jackson>2.21.1</version.com.fasterxml.jackson>
61-
<version.com.fasterxml.jackson.databind>2.21.1</version.com.fasterxml.jackson.databind>
60+
<version.com.fasterxml.jackson>2.21.2</version.com.fasterxml.jackson>
61+
<version.com.fasterxml.jackson.databind>2.21.2</version.com.fasterxml.jackson.databind>
6262
<version.com.fasterxml.jackson.annotations>2.21</version.com.fasterxml.jackson.annotations>
6363
<version.com.github.victools>4.37.0</version.com.github.victools> <!-- victools should align with Jackson if possible -->
6464
<version.com.miglayout>3.7.4</version.com.miglayout>
6565
<version.domino-slf4j-logger>1.0.1</version.domino-slf4j-logger>
6666
<version.com.google.protobuf>3.25.5</version.com.google.protobuf>
67-
<version.com.h2database>2.3.232</version.com.h2database>
67+
<version.com.h2database>2.4.240</version.com.h2database>
6868
<version.com.networknt.json-schema-validator>1.0.86</version.com.networknt.json-schema-validator>
6969
<version.com.sun.xml.bind>4.0.5</version.com.sun.xml.bind>
7070
<version.com.thoughtworks.xstream>1.4.21</version.com.thoughtworks.xstream>
7171
<version.guru.nidi>0.18.0</version.guru.nidi>
7272
<version.info.picocli>4.7.7</version.info.picocli>
73-
<version.io.micrometer>1.14.12</version.io.micrometer>
73+
<version.io.micrometer>1.16.4</version.io.micrometer>
7474
<version.io.quarkus>3.27.3</version.io.quarkus>
7575
<version.io.netty>4.1.132.Final</version.io.netty>
76+
<version.at.yawk.lz4.java>1.10.1</version.at.yawk.lz4.java>
7677
<version.io.smallrye.openapi.core>4.0.12</version.io.smallrye.openapi.core>
7778
<version.io.smallrye.config.core>3.13.4</version.io.smallrye.config.core>
7879
<version.org.apache.kafka>4.1.2</version.org.apache.kafka>
@@ -84,7 +85,7 @@
8485
<version.org.antlr>3.5.2</version.org.antlr>
8586
<version.org.antlr.ST4>4.0.7</version.org.antlr.ST4>
8687
<version.org.apache.ant>1.10.11</version.org.apache.ant>
87-
<version.org.apache.commons.lang3>3.18.0</version.org.apache.commons.lang3>
88+
<version.org.apache.commons.lang3>3.19.0</version.org.apache.commons.lang3>
8889
<version.org.apache.commons.math3>3.6.1</version.org.apache.commons.math3>
8990
<version.org.apache.httpcomponents.httpcore>4.4.16</version.org.apache.httpcomponents.httpcore>
9091
<version.org.apache.maven>3.9.11</version.org.apache.maven>
@@ -98,9 +99,9 @@
9899
<version.org.freemarker>2.3.34</version.org.freemarker>
99100
<version.org.glassfish.jaxb>4.0.6</version.org.glassfish.jaxb>
100101
<!--This needs to be in sync with JUnit-->
101-
<version.org.hamcrest>2.2</version.org.hamcrest>
102+
<version.org.hamcrest>3.0</version.org.hamcrest>
102103
<version.org.hsqldb>2.7.1</version.org.hsqldb>
103-
<version.org.infinispan>15.0.21.Final</version.org.infinispan>
104+
<version.org.infinispan>15.2.6.Final</version.org.infinispan>
104105
<version.org.infinispan.protostream>5.0.13.Final</version.org.infinispan.protostream>
105106
<version.org.javassist>3.26.0-GA</version.org.javassist>
106107
<version.org.jboss.narayana.tomcat>7.2.2.Final</version.org.jboss.narayana.tomcat>
@@ -121,8 +122,8 @@
121122
<version.jakarta.json-api>2.1.3</version.jakarta.json-api>
122123
<version.org.apache.openjpa>4.0.0</version.org.apache.openjpa>
123124
<version.org.jpmml.model>1.6.4</version.org.jpmml.model> <!-- jpmml-model BSD 3C license - ATTENTION 1.5.1 intentional, because 1.5.1 evaluators works with 1.5.1 -->
124-
<version.org.junit.jupiter>5.13.4</version.org.junit.jupiter>
125-
<version.org.junit.platform>1.13.4</version.org.junit.platform> <!-- Keep synchronized with junit-jupiter (middle and minor should be the same) -->
125+
<version.org.junit.jupiter>6.0.3</version.org.junit.jupiter>
126+
<version.org.junit.platform>6.0.3</version.org.junit.platform> <!-- JUnit 6 unified versioning: platform shares the jupiter version, managed by junit-bom 6.0.3 -->
126127
<version.org.mvel>2.5.2.Final</version.org.mvel>
127128
<version.org.powermock>2.0.9</version.org.powermock>
128129
<version.org.slf4j>2.0.17</version.org.slf4j>
@@ -188,7 +189,7 @@
188189

189190
<version.net.byte-buddy>1.17.6</version.net.byte-buddy>
190191

191-
<version.org.postgresql>42.7.8</version.org.postgresql>
192+
<version.org.postgresql>42.7.10</version.org.postgresql>
192193

193194
<version.ch.obermuhlner>2.0.1</version.ch.obermuhlner>
194195
<version.io.smallrye.jandex>3.4.0</version.io.smallrye.jandex>
@@ -1342,6 +1343,13 @@
13421343
</exclusion>
13431344
</exclusions>
13441345
</dependency>
1346+
1347+
<!-- CVE fix: use at.yawk.lz4:lz4-java instead of org.lz4:lz4-java -->
1348+
<dependency>
1349+
<groupId>at.yawk.lz4</groupId>
1350+
<artifactId>lz4-java</artifactId>
1351+
<version>${version.at.yawk.lz4.java}</version>
1352+
</dependency>
13451353
</dependencies>
13461354

13471355
</dependencyManagement>

0 commit comments

Comments
 (0)