]> source.dussan.org Git - archiva.git/commitdiff
Upgrading transient dependencies to address vulnerability report
authorMartin Stockhammer <martin_s@apache.org>
Tue, 25 May 2021 17:35:54 +0000 (19:35 +0200)
committerMartin Stockhammer <martin_s@apache.org>
Tue, 25 May 2021 17:35:54 +0000 (19:35 +0200)
archiva-modules/metadata/metadata-store-provider/metadata-store-cassandra/pom.xml

index 36bf6a218791d98dd627dd4f29bf671a5276a949..fc76755f21c001adad023f4580ae71b4836400c6 100644 (file)
           <groupId>com.fasterxml.jackson.core</groupId>
           <artifactId>jackson-core</artifactId>
         </exclusion>
+        <!-- Brings hibernate-validator dependency with ancient version, which is vulnerable. Not necessary for archiva. -->
         <exclusion>
           <groupId>com.addthis.metrics</groupId>
           <artifactId>reporter-config3</artifactId>
         </exclusion>
+        <!-- Version upgrade, see below -->
+        <exclusion>
+          <groupId>org.apache.tika</groupId>
+          <artifactId>tika-core</artifactId>
+        </exclusion>
       </exclusions>
     </dependency>
 
       <artifactId>jbcrypt</artifactId>
       <version>0.4</version>
     </dependency>
-    <!--
-    <dependency>
-      <groupId>org.codehaus.jackson</groupId>
-      <artifactId>jackson-core-asl</artifactId>
-      <version>1.9.13</version>
-    </dependency>
     <dependency>
-      <groupId>org.codehaus.jackson</groupId>
-      <artifactId>jackson-mapper-asl</artifactId>
-      <version>1.9.13</version>
+      <groupId>org.apache.tika</groupId>
+      <artifactId>tika-core</artifactId>
+      <version>1.26</version>
     </dependency>
-    -->
 
     <!-- Transitive dependency. Declared here to increase the version. -->
     <dependency>
       <groupId>org.jboss.logging</groupId>
       <artifactId>jboss-logging</artifactId>
     </dependency>
-    <!-- Dependency of cassandra -> replacing by new version -->
-<!--
-    <dependency>
-      <groupId>org.hibernate</groupId>
-      <artifactId>hibernate-validator</artifactId>
-      <version>4.3.2.Final</version>
-      <exclusions>
-        <exclusion>
-          <groupId>javax.validation</groupId>
-          <artifactId>validation-api</artifactId>
-        </exclusion>
-      </exclusions>
-    </dependency>
--->
+
     <!-- TEST Scope -->
     <dependency>
       <groupId>org.apache.archiva</groupId>