diff --git a/owasp-suppressions.xml b/owasp-suppressions.xml index b56c6bd5..62093c19 100644 --- a/owasp-suppressions.xml +++ b/owasp-suppressions.xml @@ -34,4 +34,13 @@ ^pkg:maven/com\.jayway\.jsonpath/json\-path@2.9.0$ CVE-2023-51074 + + + ^pkg:maven/commons\-configuration/commons\-configuration@1\..*$ + + CVE-2024-29133 + CVE-2024-29131 + diff --git a/query-service-client/build.gradle.kts b/query-service-client/build.gradle.kts index 61e183bc..55e9fb4b 100644 --- a/query-service-client/build.gradle.kts +++ b/query-service-client/build.gradle.kts @@ -7,7 +7,7 @@ plugins { dependencies { api(project(":query-service-api")) - implementation("org.hypertrace.core.grpcutils:grpc-client-utils:0.13.1") + implementation("org.hypertrace.core.grpcutils:grpc-client-utils:0.13.2") // Logging implementation("org.slf4j:slf4j-api:2.0.11") diff --git a/query-service-factory/build.gradle.kts b/query-service-factory/build.gradle.kts index 7a867d1f..295ec962 100644 --- a/query-service-factory/build.gradle.kts +++ b/query-service-factory/build.gradle.kts @@ -3,7 +3,7 @@ plugins { } dependencies { - api("org.hypertrace.core.serviceframework:platform-grpc-service-framework:0.1.64") + api("org.hypertrace.core.serviceframework:platform-grpc-service-framework:0.1.71") implementation(project(":query-service-impl")) implementation("com.google.inject:guice:5.0.1") diff --git a/query-service-impl/build.gradle.kts b/query-service-impl/build.gradle.kts index a38c3bae..951e103e 100644 --- a/query-service-impl/build.gradle.kts +++ b/query-service-impl/build.gradle.kts @@ -25,14 +25,14 @@ dependencies { implementation("org.apache.avro:avro:1.11.3") { because("CVE-2023-39410") } - implementation("org.apache.commons:commons-compress:1.24.0") { - because("CVE-2023-42503") + implementation("org.apache.commons:commons-compress:1.26.0") { + because("CVE-2024-25710") } implementation("org.apache.helix:helix-core:1.3.0") { because("CVE-2022-47500") } - implementation("org.apache.zookeeper:zookeeper:3.7.2") { - because("CVE-2023-44981") + implementation("org.apache.zookeeper:zookeeper:3.8.4") { + because("CVE-2024-23944") } implementation("org.webjars:swagger-ui:5.1.0") { because("CVE-2019-16728,CVE-2020-26870") @@ -60,9 +60,9 @@ dependencies { } api(project(":query-service-api")) api("com.typesafe:config:1.4.1") - implementation("org.hypertrace.core.grpcutils:grpc-context-utils:0.13.1") - implementation("org.hypertrace.core.grpcutils:grpc-client-utils:0.13.1") - implementation("org.hypertrace.core.grpcutils:grpc-server-rx-utils:0.13.1") + implementation("org.hypertrace.core.grpcutils:grpc-context-utils:0.13.2") + implementation("org.hypertrace.core.grpcutils:grpc-client-utils:0.13.2") + implementation("org.hypertrace.core.grpcutils:grpc-server-rx-utils:0.13.2") implementation("org.hypertrace.core.attribute.service:attribute-service-api:0.14.26") implementation("org.hypertrace.core.attribute.service:attribute-projection-registry:0.14.26") implementation("org.hypertrace.core.attribute.service:caching-attribute-service-client:0.14.26") @@ -74,12 +74,12 @@ dependencies { } implementation("org.slf4j:slf4j-api:2.0.11") implementation("commons-codec:commons-codec:1.15") - implementation("org.hypertrace.core.serviceframework:platform-metrics:0.1.64") + implementation("org.hypertrace.core.serviceframework:platform-metrics:0.1.71") implementation("com.google.protobuf:protobuf-java-util:3.22.0") implementation("com.google.guava:guava:32.1.2-jre") implementation("io.reactivex.rxjava3:rxjava:3.0.11") implementation("com.squareup.okhttp3:okhttp:4.11.0") - implementation("org.postgresql:postgresql:42.4.3") + implementation("org.postgresql:postgresql:42.4.4") implementation("io.trino:trino-jdbc:423") annotationProcessor("org.projectlombok:lombok:1.18.30") diff --git a/query-service/build.gradle.kts b/query-service/build.gradle.kts index 24c1c841..2b110136 100644 --- a/query-service/build.gradle.kts +++ b/query-service/build.gradle.kts @@ -10,8 +10,8 @@ plugins { dependencies { implementation(project(":query-service-factory")) - implementation("org.hypertrace.core.grpcutils:grpc-server-utils:0.13.1") - implementation("org.hypertrace.core.serviceframework:platform-grpc-service-framework:0.1.64") + implementation("org.hypertrace.core.grpcutils:grpc-server-utils:0.13.2") + implementation("org.hypertrace.core.serviceframework:platform-grpc-service-framework:0.1.71") implementation("org.slf4j:slf4j-api:2.0.11") implementation("com.typesafe:config:1.4.1") @@ -22,7 +22,7 @@ dependencies { integrationTestImplementation("org.testcontainers:testcontainers:1.16.2") integrationTestImplementation("org.testcontainers:junit-jupiter:1.16.2") integrationTestImplementation("org.testcontainers:kafka:1.16.2") - integrationTestImplementation("org.hypertrace.core.serviceframework:integrationtest-service-framework:0.1.64") + integrationTestImplementation("org.hypertrace.core.serviceframework:integrationtest-service-framework:0.1.71") integrationTestImplementation("com.github.stefanbirkner:system-lambda:1.2.0") integrationTestImplementation("org.apache.kafka:kafka-clients:7.2.1-ccs")