Skip to content

Commit

Permalink
Update libraries (#809)
Browse files Browse the repository at this point in the history
  • Loading branch information
jframe authored Jun 19, 2023
1 parent 07e8a43 commit 0f2d653
Show file tree
Hide file tree
Showing 2 changed files with 23 additions and 10 deletions.
10 changes: 3 additions & 7 deletions gradle/owasp-suppression.xml
Original file line number Diff line number Diff line change
@@ -1,15 +1,11 @@
<?xml version="1.0" encoding="UTF-8"?>
<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
<!-- See https://jeremylong.github.io/DependencyCheck/general/suppression.html for examples -->

<suppress>
<notes><![CDATA[
Suppress false positive for CVE-2020-8908 as it is only applicable for versions up to 30.0. We use 31.1.
Our code does not use com.google.common.io.Files.createTempDir() as well.
- https://nvd.nist.gov/vuln/detail/cve-2020-8908
- https://github.com/jeremylong/DependencyCheck/issues/5526
- https://github.com/google/guava/issues/4011
Suppress CVE-2023-35116 as this is not considered a CVE according to discussion in https://github.com/FasterXML/jackson-databind/issues/3972
]]></notes>
<cve>CVE-2020-8908</cve>
<packageUrl regex="true">^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$</packageUrl>
<vulnerabilityName>CVE-2023-35116</vulnerabilityName>
</suppress>
</suppressions>
23 changes: 20 additions & 3 deletions gradle/versions.gradle
Original file line number Diff line number Diff line change
Expand Up @@ -13,8 +13,8 @@

dependencyManagement {
dependencies {
dependency 'com.fasterxml.jackson.core:jackson-databind:2.15.0-rc3'
dependency 'com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.15.0-rc3'
dependency 'com.fasterxml.jackson.core:jackson-databind:2.15.2'
dependency 'com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.15.2'

dependencySet(group: 'com.google.errorprone', version: '2.17.0') {
entry 'error_prone_annotation'
Expand All @@ -25,7 +25,7 @@ dependencyManagement {

dependency 'tech.pegasys.tools.epchecks:errorprone-checks:1.1.1'

dependency 'com.google.guava:guava:31.1-jre'
dependency 'com.google.guava:guava:32.0.1-jre'

dependency 'commons-cli:commons-cli:1.5.0'
dependency 'commons-io:commons-io:2.11.0'
Expand Down Expand Up @@ -197,5 +197,22 @@ dependencyManagement {

dependency 'net.minidev:json-smart:2.4.10'
dependency 'com.nimbusds:nimbus-jose-jwt:9.31'

// manually overriding of io.grpc to avoid CVE-2023-32732, we can't update to latest besu metrics-core until
// we have Java 17 support in Web3Signer
/*
+--- org.hyperledger.besu.internal:metrics-core -> 22.10.3
| | | | +--- org.hyperledger.besu:plugin-api:22.10.3
| | | | | +--- org.apache.commons:commons-lang3:3.12.0
| | | | | +--- org.apache.tuweni:tuweni-bytes:2.3.1 (*)
| | | | | \--- org.apache.tuweni:tuweni-units:2.3.1 (*)
| | | | +--- io.grpc:grpc-netty:1.47.0
*/
dependencySet(group: 'io.grpc', version: '1.56.0') {
entry 'grpc-all'
entry 'grpc-core'
entry 'grpc-netty'
entry 'grpc-stub'
}
}
}

0 comments on commit 0f2d653

Please sign in to comment.