|
51 | 51 | - A version property must be specified in the format "version.{groupId}", optionally with a suffix to make it unique. |
52 | 52 | - Version properties must be sorted alphabetically (other form of sorting were found to be unclear and ambiguous). |
53 | 53 | --> |
54 | | - <version.ch.qos.logback>1.5.25</version.ch.qos.logback> |
| 54 | + <version.ch.qos.logback>1.5.32</version.ch.qos.logback> |
55 | 55 | <version.commons-codec>1.19.0</version.commons-codec> |
56 | 56 | <version.commons-collections>3.2.2</version.commons-collections> |
57 | 57 | <version.commons-logging>1.1.1</version.commons-logging> |
58 | 58 | <version.commons-io>2.20.0</version.commons-io> |
59 | 59 | <version.common-text>1.14.0</version.common-text> |
60 | | - <version.com.fasterxml.jackson>2.21.1</version.com.fasterxml.jackson> |
61 | | - <version.com.fasterxml.jackson.databind>2.21.1</version.com.fasterxml.jackson.databind> |
| 60 | + <version.com.fasterxml.jackson>2.21.2</version.com.fasterxml.jackson> |
| 61 | + <version.com.fasterxml.jackson.databind>2.21.2</version.com.fasterxml.jackson.databind> |
62 | 62 | <version.com.fasterxml.jackson.annotations>2.21</version.com.fasterxml.jackson.annotations> |
63 | 63 | <version.com.github.victools>4.37.0</version.com.github.victools> <!-- victools should align with Jackson if possible --> |
64 | 64 | <version.com.miglayout>3.7.4</version.com.miglayout> |
65 | 65 | <version.domino-slf4j-logger>1.0.1</version.domino-slf4j-logger> |
66 | 66 | <version.com.google.protobuf>3.25.5</version.com.google.protobuf> |
67 | | - <version.com.h2database>2.3.232</version.com.h2database> |
| 67 | + <version.com.h2database>2.4.240</version.com.h2database> |
68 | 68 | <version.com.networknt.json-schema-validator>1.0.86</version.com.networknt.json-schema-validator> |
69 | 69 | <version.com.sun.xml.bind>4.0.5</version.com.sun.xml.bind> |
70 | 70 | <version.com.thoughtworks.xstream>1.4.21</version.com.thoughtworks.xstream> |
71 | 71 | <version.guru.nidi>0.18.0</version.guru.nidi> |
72 | 72 | <version.info.picocli>4.7.7</version.info.picocli> |
73 | | - <version.io.micrometer>1.14.12</version.io.micrometer> |
| 73 | + <version.io.micrometer>1.16.4</version.io.micrometer> |
74 | 74 | <version.io.quarkus>3.27.3</version.io.quarkus> |
75 | 75 | <version.io.netty>4.1.132.Final</version.io.netty> |
| 76 | + <version.at.yawk.lz4.java>1.10.1</version.at.yawk.lz4.java> |
76 | 77 | <version.io.smallrye.openapi.core>4.0.12</version.io.smallrye.openapi.core> |
77 | 78 | <version.io.smallrye.config.core>3.13.4</version.io.smallrye.config.core> |
78 | 79 | <version.org.apache.kafka>4.1.2</version.org.apache.kafka> |
|
84 | 85 | <version.org.antlr>3.5.2</version.org.antlr> |
85 | 86 | <version.org.antlr.ST4>4.0.7</version.org.antlr.ST4> |
86 | 87 | <version.org.apache.ant>1.10.11</version.org.apache.ant> |
87 | | - <version.org.apache.commons.lang3>3.18.0</version.org.apache.commons.lang3> |
| 88 | + <version.org.apache.commons.lang3>3.19.0</version.org.apache.commons.lang3> |
88 | 89 | <version.org.apache.commons.math3>3.6.1</version.org.apache.commons.math3> |
89 | 90 | <version.org.apache.httpcomponents.httpcore>4.4.16</version.org.apache.httpcomponents.httpcore> |
90 | 91 | <version.org.apache.maven>3.9.11</version.org.apache.maven> |
|
98 | 99 | <version.org.freemarker>2.3.34</version.org.freemarker> |
99 | 100 | <version.org.glassfish.jaxb>4.0.6</version.org.glassfish.jaxb> |
100 | 101 | <!--This needs to be in sync with JUnit--> |
101 | | - <version.org.hamcrest>2.2</version.org.hamcrest> |
| 102 | + <version.org.hamcrest>3.0</version.org.hamcrest> |
102 | 103 | <version.org.hsqldb>2.7.1</version.org.hsqldb> |
103 | | - <version.org.infinispan>15.0.21.Final</version.org.infinispan> |
| 104 | + <version.org.infinispan>15.2.6.Final</version.org.infinispan> |
104 | 105 | <version.org.infinispan.protostream>5.0.13.Final</version.org.infinispan.protostream> |
105 | 106 | <version.org.javassist>3.26.0-GA</version.org.javassist> |
106 | 107 | <version.org.jboss.narayana.tomcat>7.2.2.Final</version.org.jboss.narayana.tomcat> |
|
121 | 122 | <version.jakarta.json-api>2.1.3</version.jakarta.json-api> |
122 | 123 | <version.org.apache.openjpa>4.0.0</version.org.apache.openjpa> |
123 | 124 | <version.org.jpmml.model>1.6.4</version.org.jpmml.model> <!-- jpmml-model BSD 3C license - ATTENTION 1.5.1 intentional, because 1.5.1 evaluators works with 1.5.1 --> |
124 | | - <version.org.junit.jupiter>5.13.4</version.org.junit.jupiter> |
125 | | - <version.org.junit.platform>1.13.4</version.org.junit.platform> <!-- Keep synchronized with junit-jupiter (middle and minor should be the same) --> |
| 125 | + <version.org.junit.jupiter>6.0.3</version.org.junit.jupiter> |
| 126 | + <version.org.junit.platform>6.0.3</version.org.junit.platform> <!-- JUnit 6 unified versioning: platform shares the jupiter version, managed by junit-bom 6.0.3 --> |
126 | 127 | <version.org.mvel>2.5.2.Final</version.org.mvel> |
127 | 128 | <version.org.powermock>2.0.9</version.org.powermock> |
128 | 129 | <version.org.slf4j>2.0.17</version.org.slf4j> |
|
188 | 189 |
|
189 | 190 | <version.net.byte-buddy>1.17.6</version.net.byte-buddy> |
190 | 191 |
|
191 | | - <version.org.postgresql>42.7.8</version.org.postgresql> |
| 192 | + <version.org.postgresql>42.7.10</version.org.postgresql> |
192 | 193 |
|
193 | 194 | <version.ch.obermuhlner>2.0.1</version.ch.obermuhlner> |
194 | 195 | <version.io.smallrye.jandex>3.4.0</version.io.smallrye.jandex> |
|
1342 | 1343 | </exclusion> |
1343 | 1344 | </exclusions> |
1344 | 1345 | </dependency> |
| 1346 | + |
| 1347 | + <!-- CVE fix: use at.yawk.lz4:lz4-java instead of org.lz4:lz4-java --> |
| 1348 | + <dependency> |
| 1349 | + <groupId>at.yawk.lz4</groupId> |
| 1350 | + <artifactId>lz4-java</artifactId> |
| 1351 | + <version>${version.at.yawk.lz4.java}</version> |
| 1352 | + </dependency> |
1345 | 1353 | </dependencies> |
1346 | 1354 |
|
1347 | 1355 | </dependencyManagement> |
|
0 commit comments