@@ -25,18 +25,28 @@ repositories {
2525dependencies {
2626 implementation ' javax.activation:activation:1.1.1'
2727 implementation ' org.slf4j:slf4j-api:1.7.36'
28- implementation ' ch.qos.logback:logback-core:1.2.11'
29- implementation ' ch.qos.logback:logback-classic:1.2.11'
28+ implementation ' ch.qos.logback:logback-core:1.5.18'
29+ implementation ' ch.qos.logback:logback-classic:1.5.18'
30+
3031 implementation ' io.seqera.tower:tower-java-sdk:1.43.1'
32+ // Upgrade transitive Jersey client dependencies to non-vulnerable 2.x version
33+ implementation " org.glassfish.jersey.core:jersey-client:2.47"
34+ implementation " org.glassfish.jersey.media:jersey-media-multipart:2.47"
35+ implementation " org.glassfish.jersey.media:jersey-media-json-jackson:2.47"
36+ implementation " org.glassfish.jersey.inject:jersey-hk2:2.47"
37+
3138 implementation ' info.picocli:picocli:4.6.3'
32- implementation ' org.apache.commons:commons-compress:1.22 '
39+ implementation ' org.apache.commons:commons-compress:1.28.0 '
3340 implementation ' org.tukaani:xz:1.9'
3441 implementation ' io.github.classgraph:classgraph:4.8.165'
3542 annotationProcessor ' info.picocli:picocli-codegen:4.6.3'
3643
37- testImplementation ' org.mock-server:mockserver-client-java:5.13.0'
38- testImplementation ' org.mock-server:mockserver-netty:5.13.0'
39- testImplementation ' org.mock-server:mockserver-junit-jupiter:5.13.0'
44+ testImplementation ' org.mock-server:mockserver-client-java:5.15.0'
45+ testImplementation ' org.mock-server:mockserver-netty:5.15.0'
46+ testImplementation ' org.mock-server:mockserver-junit-jupiter:5.15.0'
47+ // Upgrade transitive mock-server dependencies to non-vulnerable 2.x version
48+ testImplementation ' commons-io:commons-io:2.20.0'
49+
4050 testImplementation ' org.junit.jupiter:junit-jupiter-api:5.8.2'
4151 testImplementation ' org.junit.jupiter:junit-jupiter-params:5.8.2'
4252 testRuntimeOnly ' org.junit.jupiter:junit-jupiter-engine:5.8.2'
0 commit comments