Skip to content

Commit 13e6ccf

Browse files
Dhamodhar-DDRDhamodhar Reddy  Dakannagari
andauthored
updated service framework version (#222)
* updated servie framework version * Update postgresql version update postgresql version to 42.4.4 to resolve CVE-2024-1597 vulnerability * Update org.apache.commons version update org.apache.commons version to 1.26.0 to resolve CVE-2024-25710 and CVE-2024-26308 vulnerabilities * updated org.apache.zookeeper version updated to org.apache.zookeeper:zookeeper to 3.8.4 to resolve CVE-2024-23944 vulnerability * updated grpc-utils to 0.13.2 * added suppressions for CVE-2024-29133 and CVE-2024-29133 --------- Co-authored-by: Dhamodhar Reddy Dakannagari <[email protected]>
1 parent defb003 commit 13e6ccf

File tree

5 files changed

+23
-14
lines changed

5 files changed

+23
-14
lines changed

owasp-suppressions.xml

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -34,4 +34,13 @@
3434
<packageUrl regex="true">^pkg:maven/com\.jayway\.jsonpath/json\[email protected]$</packageUrl>
3535
<vulnerabilityName>CVE-2023-51074</vulnerabilityName>
3636
</suppress>
37+
<suppress>
38+
<notes><![CDATA[
39+
CVE-2024-29133, CVE-2024-29131 only impacts commons-configuration 2+, which is already fixed. Commons configuration 1 is a different artifact and unimpacted.
40+
]]></notes>
41+
<packageUrl regex="true">^pkg:maven/commons\-configuration/commons\-configuration@1\..*$
42+
</packageUrl>
43+
<vulnerabilityName>CVE-2024-29133</vulnerabilityName>
44+
<vulnerabilityName>CVE-2024-29131</vulnerabilityName>
45+
</suppress>
3746
</suppressions>

query-service-client/build.gradle.kts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ plugins {
77

88
dependencies {
99
api(project(":query-service-api"))
10-
implementation("org.hypertrace.core.grpcutils:grpc-client-utils:0.13.1")
10+
implementation("org.hypertrace.core.grpcutils:grpc-client-utils:0.13.2")
1111

1212
// Logging
1313
implementation("org.slf4j:slf4j-api:2.0.11")

query-service-factory/build.gradle.kts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ plugins {
33
}
44

55
dependencies {
6-
api("org.hypertrace.core.serviceframework:platform-grpc-service-framework:0.1.64")
6+
api("org.hypertrace.core.serviceframework:platform-grpc-service-framework:0.1.71")
77

88
implementation(project(":query-service-impl"))
99
implementation("com.google.inject:guice:5.0.1")

query-service-impl/build.gradle.kts

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -25,14 +25,14 @@ dependencies {
2525
implementation("org.apache.avro:avro:1.11.3") {
2626
because("CVE-2023-39410")
2727
}
28-
implementation("org.apache.commons:commons-compress:1.24.0") {
29-
because("CVE-2023-42503")
28+
implementation("org.apache.commons:commons-compress:1.26.0") {
29+
because("CVE-2024-25710")
3030
}
3131
implementation("org.apache.helix:helix-core:1.3.0") {
3232
because("CVE-2022-47500")
3333
}
34-
implementation("org.apache.zookeeper:zookeeper:3.7.2") {
35-
because("CVE-2023-44981")
34+
implementation("org.apache.zookeeper:zookeeper:3.8.4") {
35+
because("CVE-2024-23944")
3636
}
3737
implementation("org.webjars:swagger-ui:5.1.0") {
3838
because("CVE-2019-16728,CVE-2020-26870")
@@ -60,9 +60,9 @@ dependencies {
6060
}
6161
api(project(":query-service-api"))
6262
api("com.typesafe:config:1.4.1")
63-
implementation("org.hypertrace.core.grpcutils:grpc-context-utils:0.13.1")
64-
implementation("org.hypertrace.core.grpcutils:grpc-client-utils:0.13.1")
65-
implementation("org.hypertrace.core.grpcutils:grpc-server-rx-utils:0.13.1")
63+
implementation("org.hypertrace.core.grpcutils:grpc-context-utils:0.13.2")
64+
implementation("org.hypertrace.core.grpcutils:grpc-client-utils:0.13.2")
65+
implementation("org.hypertrace.core.grpcutils:grpc-server-rx-utils:0.13.2")
6666
implementation("org.hypertrace.core.attribute.service:attribute-service-api:0.14.26")
6767
implementation("org.hypertrace.core.attribute.service:attribute-projection-registry:0.14.26")
6868
implementation("org.hypertrace.core.attribute.service:caching-attribute-service-client:0.14.26")
@@ -74,12 +74,12 @@ dependencies {
7474
}
7575
implementation("org.slf4j:slf4j-api:2.0.11")
7676
implementation("commons-codec:commons-codec:1.15")
77-
implementation("org.hypertrace.core.serviceframework:platform-metrics:0.1.64")
77+
implementation("org.hypertrace.core.serviceframework:platform-metrics:0.1.71")
7878
implementation("com.google.protobuf:protobuf-java-util:3.22.0")
7979
implementation("com.google.guava:guava:32.1.2-jre")
8080
implementation("io.reactivex.rxjava3:rxjava:3.0.11")
8181
implementation("com.squareup.okhttp3:okhttp:4.11.0")
82-
implementation("org.postgresql:postgresql:42.4.3")
82+
implementation("org.postgresql:postgresql:42.4.4")
8383
implementation("io.trino:trino-jdbc:423")
8484

8585
annotationProcessor("org.projectlombok:lombok:1.18.30")

query-service/build.gradle.kts

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -10,8 +10,8 @@ plugins {
1010

1111
dependencies {
1212
implementation(project(":query-service-factory"))
13-
implementation("org.hypertrace.core.grpcutils:grpc-server-utils:0.13.1")
14-
implementation("org.hypertrace.core.serviceframework:platform-grpc-service-framework:0.1.64")
13+
implementation("org.hypertrace.core.grpcutils:grpc-server-utils:0.13.2")
14+
implementation("org.hypertrace.core.serviceframework:platform-grpc-service-framework:0.1.71")
1515
implementation("org.slf4j:slf4j-api:2.0.11")
1616
implementation("com.typesafe:config:1.4.1")
1717

@@ -22,7 +22,7 @@ dependencies {
2222
integrationTestImplementation("org.testcontainers:testcontainers:1.16.2")
2323
integrationTestImplementation("org.testcontainers:junit-jupiter:1.16.2")
2424
integrationTestImplementation("org.testcontainers:kafka:1.16.2")
25-
integrationTestImplementation("org.hypertrace.core.serviceframework:integrationtest-service-framework:0.1.64")
25+
integrationTestImplementation("org.hypertrace.core.serviceframework:integrationtest-service-framework:0.1.71")
2626
integrationTestImplementation("com.github.stefanbirkner:system-lambda:1.2.0")
2727

2828
integrationTestImplementation("org.apache.kafka:kafka-clients:7.2.1-ccs")

0 commit comments

Comments
 (0)