Skip to content

Commit ef87db5

Browse files
committed
Updated depedencies to align with Spring Boot 3.4.2
1 parent 4f6fc87 commit ef87db5

File tree

3 files changed

+22
-30
lines changed

3 files changed

+22
-30
lines changed

README.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -121,7 +121,7 @@ $ docker compose -f docker-compose.yml -f docker-compose.service.yml up -d
121121
The cURL commands above can again be used to test the API.
122122

123123
Grafana
124-
=======
124+
-------
125125

126126
Spring Boot 3.4.0 extended the Docker Compose support to support
127127
[Grafana LGTM](https://grafana.com/blog/2024/03/13/an-opentelemetry-backend-in-a-docker-image-introducing-grafana/otel-lgtm/).

config/owasp/suppress.xml

+3-17
Original file line numberDiff line numberDiff line change
@@ -3,23 +3,9 @@
33
<!-- Suppressing all reported CVEs as project is for demo purposes only -->
44
<suppress>
55
<notes><![CDATA[
6-
file name: jackson-databind-2.15.3.jar
6+
file name: protobuf-java-3.23.4.jar
77
]]></notes>
8-
<packageUrl regex="true">^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$</packageUrl>
9-
<cve>CVE-2023-35116</cve>
10-
</suppress>
11-
<suppress>
12-
<notes><![CDATA[
13-
file name: logback-core-1.5.12.jar
14-
]]></notes>
15-
<packageUrl regex="true">^pkg:maven/ch\.qos\.logback/logback\-core@.*$</packageUrl>
16-
<vulnerabilityName>CVE-2024-12798</vulnerabilityName>
17-
</suppress>
18-
<suppress>
19-
<notes><![CDATA[
20-
file name: logback-core-1.5.12.jar
21-
]]></notes>
22-
<packageUrl regex="true">^pkg:maven/ch\.qos\.logback/logback\-core@.*$</packageUrl>
23-
<vulnerabilityName>CVE-2024-12801</vulnerabilityName>
8+
<packageUrl regex="true">^pkg:maven/com\.google\.protobuf/protobuf-java@.*$</packageUrl>
9+
<vulnerabilityName>CVE-2024-7254</vulnerabilityName>
2410
</suppress>
2511
</suppressions>

pom.xml

+18-12
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
<parent>
77
<groupId>org.springframework.boot</groupId>
88
<artifactId>spring-boot-starter-parent</artifactId>
9-
<version>3.4.1</version>
9+
<version>3.4.2</version>
1010
<relativePath /> <!-- lookup parent from repository -->
1111
</parent>
1212

@@ -32,37 +32,39 @@
3232
<!-- Dependency versions -->
3333
<commons-collections.version>4.4</commons-collections.version>
3434
<findbugs-jsr305.version>3.0.2</findbugs-jsr305.version>
35-
<opentelemtry-instrumentation.version>2.10.0</opentelemtry-instrumentation.version>
36-
<spt-development-audit-spring-boot.version>3.4.1</spt-development-audit-spring-boot.version>
37-
<spt-development-cid-jms-spring-boot.version>3.4.1</spt-development-cid-jms-spring-boot.version>
38-
<spt-development-cid-web-spring-boot.version>3.4.1</spt-development-cid-web-spring-boot.version>
39-
<spt-development-logging-spring-boot.version>3.4.1</spt-development-logging-spring-boot.version>
35+
<!-- Remove dependencyManagement entry for opentelemtry-semconv when upgrading opentelemtry-instrumentation -->
36+
<opentelemtry-instrumentation.version>2.12.0</opentelemtry-instrumentation.version>
37+
<opentelemtry-semconv.version>1.29.0-alpha</opentelemtry-semconv.version>
38+
<spt-development-audit-spring-boot.version>3.4.2</spt-development-audit-spring-boot.version>
39+
<spt-development-cid-jms-spring-boot.version>3.4.2</spt-development-cid-jms-spring-boot.version>
40+
<spt-development-cid-web-spring-boot.version>3.4.2</spt-development-cid-web-spring-boot.version>
41+
<spt-development-logging-spring-boot.version>3.4.2</spt-development-logging-spring-boot.version>
4042

4143
<!-- Test dependency versions -->
4244
<archunit.version>1.3.0</archunit.version>
4345
<awaitility.version>4.2.2</awaitility.version>
4446
<cucumber.version>7.20.1</cucumber.version>
4547
<junit-platform.version>1.11.4</junit-platform.version>
46-
<spt-development-test.version>3.1.14</spt-development-test.version>
48+
<spt-development-test.version>3.1.15</spt-development-test.version>
4749
<testcontainers.version>1.20.4</testcontainers.version>
4850

4951
<!-- Plugin versions -->
5052
<checkstyle-maven-plugin.version>3.6.0</checkstyle-maven-plugin.version>
51-
<dependency-check-maven.version>11.1.1</dependency-check-maven.version>
53+
<dependency-check-maven.version>12.0.1</dependency-check-maven.version>
5254
<jacoco-maven-plugin.version>0.8.12</jacoco-maven-plugin.version>
5355
<license-maven-plugin.version>2.5.0</license-maven-plugin.version>
5456
<maven-jxr-plugin.version>3.6.0</maven-jxr-plugin.version>
5557
<maven-pmd-plugin.version>3.26.0</maven-pmd-plugin.version>
5658
<maven-scm-plugin.version>2.1.0</maven-scm-plugin.version>
57-
<pitest-maven.version>1.17.3</pitest-maven.version>
59+
<pitest-maven.version>1.17.4</pitest-maven.version>
5860
<spotbugs-plugin.version>4.8.6.6</spotbugs-plugin.version>
5961

6062
<!-- Plugin dependencies -->
61-
<checkstyle.version>10.21.0</checkstyle.version>
63+
<checkstyle.version>10.21.2</checkstyle.version>
6264
<findbugs-slf4j-bug-pattern.version>1.5.0</findbugs-slf4j-bug-pattern.version>
6365
<findbugs-sec-bug-pattern.version>1.13.0</findbugs-sec-bug-pattern.version>
6466
<pitest-junit5-plugin.version>1.2.1</pitest-junit5-plugin.version>
65-
<pmd.version>7.8.0</pmd.version>
67+
<pmd.version>7.9.0</pmd.version>
6668
</properties>
6769

6870
<dependencyManagement>
@@ -94,7 +96,11 @@
9496
</dependency>
9597

9698
<!-- Dependencies added to avoid dependency convergence errors -->
97-
<!-- None -->
99+
<dependency>
100+
<groupId>io.opentelemetry.semconv</groupId>
101+
<artifactId>opentelemetry-semconv</artifactId>
102+
<version>${opentelemtry-semconv.version}</version>
103+
</dependency>
98104
</dependencies>
99105
</dependencyManagement>
100106

0 commit comments

Comments
 (0)