diff --git a/owasp-suppressions.xml b/owasp-suppressions.xml
index b56c6bd5..62093c19 100644
--- a/owasp-suppressions.xml
+++ b/owasp-suppressions.xml
@@ -34,4 +34,13 @@
^pkg:maven/com\.jayway\.jsonpath/json\-path@2.9.0$
CVE-2023-51074
+
+
+ ^pkg:maven/commons\-configuration/commons\-configuration@1\..*$
+
+ CVE-2024-29133
+ CVE-2024-29131
+
diff --git a/query-service-client/build.gradle.kts b/query-service-client/build.gradle.kts
index 61e183bc..55e9fb4b 100644
--- a/query-service-client/build.gradle.kts
+++ b/query-service-client/build.gradle.kts
@@ -7,7 +7,7 @@ plugins {
dependencies {
api(project(":query-service-api"))
- implementation("org.hypertrace.core.grpcutils:grpc-client-utils:0.13.1")
+ implementation("org.hypertrace.core.grpcutils:grpc-client-utils:0.13.2")
// Logging
implementation("org.slf4j:slf4j-api:2.0.11")
diff --git a/query-service-factory/build.gradle.kts b/query-service-factory/build.gradle.kts
index 7a867d1f..295ec962 100644
--- a/query-service-factory/build.gradle.kts
+++ b/query-service-factory/build.gradle.kts
@@ -3,7 +3,7 @@ plugins {
}
dependencies {
- api("org.hypertrace.core.serviceframework:platform-grpc-service-framework:0.1.64")
+ api("org.hypertrace.core.serviceframework:platform-grpc-service-framework:0.1.71")
implementation(project(":query-service-impl"))
implementation("com.google.inject:guice:5.0.1")
diff --git a/query-service-impl/build.gradle.kts b/query-service-impl/build.gradle.kts
index a38c3bae..951e103e 100644
--- a/query-service-impl/build.gradle.kts
+++ b/query-service-impl/build.gradle.kts
@@ -25,14 +25,14 @@ dependencies {
implementation("org.apache.avro:avro:1.11.3") {
because("CVE-2023-39410")
}
- implementation("org.apache.commons:commons-compress:1.24.0") {
- because("CVE-2023-42503")
+ implementation("org.apache.commons:commons-compress:1.26.0") {
+ because("CVE-2024-25710")
}
implementation("org.apache.helix:helix-core:1.3.0") {
because("CVE-2022-47500")
}
- implementation("org.apache.zookeeper:zookeeper:3.7.2") {
- because("CVE-2023-44981")
+ implementation("org.apache.zookeeper:zookeeper:3.8.4") {
+ because("CVE-2024-23944")
}
implementation("org.webjars:swagger-ui:5.1.0") {
because("CVE-2019-16728,CVE-2020-26870")
@@ -60,9 +60,9 @@ dependencies {
}
api(project(":query-service-api"))
api("com.typesafe:config:1.4.1")
- implementation("org.hypertrace.core.grpcutils:grpc-context-utils:0.13.1")
- implementation("org.hypertrace.core.grpcutils:grpc-client-utils:0.13.1")
- implementation("org.hypertrace.core.grpcutils:grpc-server-rx-utils:0.13.1")
+ implementation("org.hypertrace.core.grpcutils:grpc-context-utils:0.13.2")
+ implementation("org.hypertrace.core.grpcutils:grpc-client-utils:0.13.2")
+ implementation("org.hypertrace.core.grpcutils:grpc-server-rx-utils:0.13.2")
implementation("org.hypertrace.core.attribute.service:attribute-service-api:0.14.26")
implementation("org.hypertrace.core.attribute.service:attribute-projection-registry:0.14.26")
implementation("org.hypertrace.core.attribute.service:caching-attribute-service-client:0.14.26")
@@ -74,12 +74,12 @@ dependencies {
}
implementation("org.slf4j:slf4j-api:2.0.11")
implementation("commons-codec:commons-codec:1.15")
- implementation("org.hypertrace.core.serviceframework:platform-metrics:0.1.64")
+ implementation("org.hypertrace.core.serviceframework:platform-metrics:0.1.71")
implementation("com.google.protobuf:protobuf-java-util:3.22.0")
implementation("com.google.guava:guava:32.1.2-jre")
implementation("io.reactivex.rxjava3:rxjava:3.0.11")
implementation("com.squareup.okhttp3:okhttp:4.11.0")
- implementation("org.postgresql:postgresql:42.4.3")
+ implementation("org.postgresql:postgresql:42.4.4")
implementation("io.trino:trino-jdbc:423")
annotationProcessor("org.projectlombok:lombok:1.18.30")
diff --git a/query-service/build.gradle.kts b/query-service/build.gradle.kts
index 24c1c841..2b110136 100644
--- a/query-service/build.gradle.kts
+++ b/query-service/build.gradle.kts
@@ -10,8 +10,8 @@ plugins {
dependencies {
implementation(project(":query-service-factory"))
- implementation("org.hypertrace.core.grpcutils:grpc-server-utils:0.13.1")
- implementation("org.hypertrace.core.serviceframework:platform-grpc-service-framework:0.1.64")
+ implementation("org.hypertrace.core.grpcutils:grpc-server-utils:0.13.2")
+ implementation("org.hypertrace.core.serviceframework:platform-grpc-service-framework:0.1.71")
implementation("org.slf4j:slf4j-api:2.0.11")
implementation("com.typesafe:config:1.4.1")
@@ -22,7 +22,7 @@ dependencies {
integrationTestImplementation("org.testcontainers:testcontainers:1.16.2")
integrationTestImplementation("org.testcontainers:junit-jupiter:1.16.2")
integrationTestImplementation("org.testcontainers:kafka:1.16.2")
- integrationTestImplementation("org.hypertrace.core.serviceframework:integrationtest-service-framework:0.1.64")
+ integrationTestImplementation("org.hypertrace.core.serviceframework:integrationtest-service-framework:0.1.71")
integrationTestImplementation("com.github.stefanbirkner:system-lambda:1.2.0")
integrationTestImplementation("org.apache.kafka:kafka-clients:7.2.1-ccs")