From 9cb3864ef13bdfb3bdb6b146b35b5b4925cd727c Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Wed, 17 Jan 2024 13:40:50 +0000 Subject: [PATCH 1/2] fix: api/codegeex-api-example-java/pom.xml to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1009829 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1047324 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1048302 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052449 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1052450 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1054588 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056414 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056416 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056417 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056418 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056419 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056420 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056421 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056424 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056425 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056426 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1056427 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-1061931 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-174736 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-2421244 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038424 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-3038426 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-31507 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-31519 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-31520 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-31573 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-32043 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-32044 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-32111 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450207 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-450917 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-455617 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467014 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467015 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-467016 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469674 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-469676 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-471943 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-472980 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-540500 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-548451 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559094 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-559106 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560762 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-560766 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561362 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561373 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561585 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561586 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-561587 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-564887 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-564888 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572300 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-6056407 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-608664 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72445 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72446 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72447 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72448 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72449 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72450 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72451 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72882 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72883 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-72884 - https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONDATATYPE-173759 - https://snyk.io/vuln/SNYK-JAVA-COMSQUAREUPOKIO-5820002 - https://snyk.io/vuln/SNYK-JAVA-ORGJETBRAINSKOTLIN-2393744 --- api/codegeex-api-example-java/pom.xml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/api/codegeex-api-example-java/pom.xml b/api/codegeex-api-example-java/pom.xml index 03d01d8..7a4094c 100644 --- a/api/codegeex-api-example-java/pom.xml +++ b/api/codegeex-api-example-java/pom.xml @@ -57,17 +57,17 @@ com.fasterxml.jackson.module jackson-module-parameter-names - 2.6.6 + 2.13.5 com.fasterxml.jackson.datatype jackson-datatype-jdk8 - 2.6.6 + 2.13.5 com.fasterxml.jackson.datatype jackson-datatype-jsr310 - 2.6.6 + 2.13.5 com.squareup.okhttp3 @@ -109,7 +109,7 @@ com.squareup.okhttp3 okhttp - 4.10.0 + 4.12.0 log4j From d0dca1207944de1dad3d18e4c4135f06062526a8 Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 9 Sep 2024 03:40:09 +0000 Subject: [PATCH 2/2] fix: upgrade multiple dependencies with Snyk Snyk has created this PR to upgrade: - com.fasterxml.jackson.datatype:jackson-datatype-jdk8 from 2.13.5 to 2.17.2. See this package in maven: https://mvnrepository.com/artifact/com.fasterxml.jackson.datatype/jackson-datatype-jdk8/ - com.fasterxml.jackson.datatype:jackson-datatype-jsr310 from 2.13.5 to 2.17.2. See this package in maven: https://mvnrepository.com/artifact/com.fasterxml.jackson.datatype/jackson-datatype-jsr310/ - com.fasterxml.jackson.module:jackson-module-parameter-names from 2.13.5 to 2.17.2. See this package in maven: https://mvnrepository.com/artifact/com.fasterxml.jackson.module/jackson-module-parameter-names/ - org.projectlombok:lombok from 1.18.20 to 1.18.34. See this package in maven: https://mvnrepository.com/artifact/org.projectlombok/lombok/ - org.slf4j:slf4j-log4j12 from 1.7.5 to 1.7.36. See this package in maven: https://mvnrepository.com/artifact/org.slf4j/slf4j-log4j12/ See this project in Snyk: https://app.snyk.io/org/mihaib18/project/127457af-6770-4650-a720-bd9ff55e1473?utm_source=github&utm_medium=referral&page=upgrade-pr --- api/codegeex-api-example-java/pom.xml | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/api/codegeex-api-example-java/pom.xml b/api/codegeex-api-example-java/pom.xml index 7a4094c..3c1a556 100644 --- a/api/codegeex-api-example-java/pom.xml +++ b/api/codegeex-api-example-java/pom.xml @@ -57,17 +57,17 @@ com.fasterxml.jackson.module jackson-module-parameter-names - 2.13.5 + 2.17.2 com.fasterxml.jackson.datatype jackson-datatype-jdk8 - 2.13.5 + 2.17.2 com.fasterxml.jackson.datatype jackson-datatype-jsr310 - 2.13.5 + 2.17.2 com.squareup.okhttp3 @@ -119,12 +119,12 @@ org.slf4j slf4j-log4j12 - 1.7.5 + 1.7.36 org.projectlombok lombok - 1.18.20 + 1.18.34 provided