NOAA-OWP / wres

Code and scripts for the Water Resources Evaluation Service
Other
2 stars 1 forks source link

As a system admin, I want dependency (library, package, image, configuration) updates for security and bug fixes for WRES 6.27 #340

Closed epag closed 1 month ago

epag commented 1 month ago

The deployment ticket is .

Known Issues: https://github.com/NOAA-OWP/wres/issues/68 https://github.com/NOAA-OWP/wres/issues/70

epag commented 1 month ago

Results of dependencyUpdate


> Configure project :
20241017-2822193
20241017-2822193

> Task :dependencyUpdates

------------------------------------------------------------
: Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - com.adarshr.test-logger:com.adarshr.test-logger.gradle.plugin:4.0.0
 - com.atlassian.commonmark:commonmark:0.17.0
 - com.github.ben-manes.caffeine:caffeine:3.1.8
 - com.github.ben-manes.versions:com.github.ben-manes.versions.gradle.plugin:0.51.0
 - com.github.marschall:jfr-jdbc:0.4.0
 - com.github.seanrl.jaxb:com.github.seanrl.jaxb.gradle.plugin:2.5.4
 - com.google.jimfs:jimfs:1.3.0
 - com.h2database:h2:2.3.232
 - com.hubspot.jackson:jackson-datatype-protobuf:0.9.15
 - com.mattbertolini:liquibase-slf4j:5.0.0
 - com.netflix.nebula:gradle-aggregate-javadocs-plugin:3.0.1
 - com.opencsv:opencsv:5.9
 - com.sun.xml.fastinfoset:FastInfoset:2.1.1
 - commons-beanutils:commons-beanutils:1.9.4
 - commons-codec:commons-codec:1.17.1
 - de.undercouch.download:de.undercouch.download.gradle.plugin:5.6.0
 - io.swagger.core.v3:swagger-jaxrs2:2.2.23
 - jakarta.jms:jakarta.jms-api:3.1.0
 - javax.measure:unit-api:2.2
 - javax.servlet:javax.servlet-api:3.1.0
 - javax.ws.rs:javax.ws.rs-api:2.1
 - junit:junit:4.13.2
 - org.apache.activemq:artemis-amqp-protocol:2.37.0
 - org.apache.activemq:artemis-server:2.37.0
 - org.apache.commons:commons-compress:1.27.1
 - org.apache.commons:commons-configuration2:2.11.0
 - org.apache.commons:commons-lang3:3.17.0
 - org.apache.commons:commons-math3:3.6.1
 - org.apache.qpid:qpid-broker-core:9.2.0
 - org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol:9.2.0
 - org.apache.qpid:qpid-broker-plugins-memory-store:9.2.0
 - org.bouncycastle:bcpkix-jdk18on:1.78.1
 - org.bouncycastle:bcprov-jdk18on:1.78.1
 - org.eclipse.jetty:jetty-webapp:11.0.24
 - org.eclipse.jetty.http2:http2-server:11.0.24
 - org.glassfish:javax.json:1.1.4
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.jfree:jfreechart:1.5.5
 - org.jvnet.jaxb2_commons:jaxb2-basics-annotate:1.1.0
 - org.kordamp.gradle.markdown:org.kordamp.gradle.markdown.gradle.plugin:2.2.0
 - org.liquibase:liquibase-core:4.29.2
 - org.locationtech.jts:jts-core:1.20.0
 - org.locationtech.jts:jts-io:1.20.0
 - org.mock-server:mockserver-netty:5.15.0
 - org.mockito:mockito-inline:5.2.0
 - org.postgresql:postgresql:42.7.4
 - org.projectlombok:lombok:1.18.34
 - org.slf4j:jcl-over-slf4j:2.1.0-alpha1
 - org.slf4j:jul-to-slf4j:2.1.0-alpha1
 - org.slf4j:log4j-over-slf4j:2.1.0-alpha1
 - org.sonarqube:org.sonarqube.gradle.plugin:5.1.0.4882
 - si.uom:si-units:2.1
 - systems.uom:systems-quantity:2.1
 - systems.uom:systems-ucum:2.1
 - tech.units:indriya:2.2

The following dependencies have later milestone versions:
 - ch.qos.logback:logback-classic [1.5.8 -> 1.5.11]
     http://logback.qos.ch
 - com.fasterxml.jackson:jackson-bom [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson-bom
 - com.fasterxml.jackson.core:jackson-annotations [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson
 - com.fasterxml.jackson.core:jackson-core [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson-core
 - com.fasterxml.jackson.core:jackson-databind [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson
 - com.fasterxml.jackson.dataformat:jackson-dataformat-yaml [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson-dataformats-text
 - com.fasterxml.jackson.datatype:jackson-datatype-jsr310 [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson-modules-java8
 - com.github.sabomichal:immutable-xjc-plugin [1.7.1 -> 2.0.3]
     https://github.com/sabomichal/immutable-xjc
 - com.google.guava:guava [33.3.0-jre -> 33.3.1-jre]
     https://github.com/google/guava
 - com.google.guava:guava-testlib [33.3.0-jre -> 33.3.1-jre]
     https://github.com/google/guava
 - com.google.protobuf:com.google.protobuf.gradle.plugin [0.9.1 -> 0.9.4]
 - com.google.protobuf:protobuf-java [3.21.12 -> 4.29.0-RC1]
     https://developers.google.com/protocol-buffers/
 - com.google.protobuf:protobuf-java-util [3.21.12 -> 4.29.0-RC1]
     https://developers.google.com/protocol-buffers/
 - com.google.protobuf:protoc [3.21.12 -> 21.0-rc-1]
     https://developers.google.com/protocol-buffers/
 - com.networknt:json-schema-validator [1.5.1 -> 1.5.2]
     https://github.com/networknt/json-schema-validator
 - com.rabbitmq:amqp-client [5.21.0 -> 5.22.0]
     https://www.rabbitmq.com
 - com.squareup.okhttp3:okhttp [4.12.0 -> 5.0.0-alpha.14]
     https://square.github.io/okhttp/
 - com.zaxxer:HikariCP [5.1.0 -> 6.0.0]
     https://github.com/brettwooldridge/HikariCP
 - commons-io:commons-io [2.16.1 -> 2.17.0]
     https://commons.apache.org/proper/commons-io/
 - edu.ucar:cdm-core [5.4.2 -> 6.0.0-beta1]
 - io.netty:netty-all [4.1.111.Final -> 5.0.0.Alpha2]
     http://netty.io/
 - io.soabase.record-builder:record-builder-core [41 -> 43]
     https://github.com/randgalt/record-builder
 - io.soabase.record-builder:record-builder-processor [41 -> 43]
     https://github.com/randgalt/record-builder
 - io.swagger.core.v3:swagger-jaxrs2-jakarta [2.2.23 -> 2.2.25]
     https://github.com/swagger-api/swagger-core
 - io.swagger.core.v3.swagger-gradle-plugin:io.swagger.core.v3.swagger-gradle-plugin.gradle.plugin [2.2.23 -> 2.2.25]
 - jakarta.activation:jakarta.activation-api [1.2.2 -> 2.1.3]
     https://github.com/jakartaee/jaf-api
 - jakarta.annotation:jakarta.annotation-api [2.1.1 -> 3.0.0]
     https://projects.eclipse.org/projects/ee4j.ca
 - jakarta.ws.rs:jakarta.ws.rs-api [3.1.0 -> 4.0.0]
     https://github.com/jakartaee/rest
 - jakarta.xml.bind:jakarta.xml.bind-api [2.3.3 -> 4.0.2]
     https://github.com/jakartaee/jaxb-api
 - jakarta.xml.bind:jakarta.xml.bind-api [3.0.1 -> 4.0.2]
     https://github.com/jakartaee/jaxb-api
 - org.ajoberstar.grgit:org.ajoberstar.grgit.gradle.plugin [5.2.2 -> 5.3.0]
     https://github.com/ajoberstar/grgit
 - org.apache.commons:commons-collections4 [4.4 -> 4.5.0-M2]
     https://commons.apache.org/proper/commons-collections/
 - org.apache.commons:commons-lang3 [3.12.0 -> 3.17.0]
     https://commons.apache.org/proper/commons-lang/
 - org.apache.qpid:qpid-jms-client [2.5.0 -> 2.6.1]
     https://qpid.apache.org
 - org.apache.tika:tika-core [2.9.2 -> 3.0.0-BETA2]
     https://tika.apache.org/
 - org.beryx.jlink:org.beryx.jlink.gradle.plugin [2.26.0 -> 3.0.1]
 - org.eclipse.collections:eclipse-collections [11.1.0 -> 12.0.0.M3]
     https://github.com/eclipse/eclipse-collections
 - org.eclipse.jetty:jetty-alpn-java-server [11.0.24 -> 12.0.14]
     https://jetty.org
 - org.eclipse.jetty:jetty-server [11.0.24 -> 12.0.14]
     https://jetty.org
 - org.eclipse.persistence:org.eclipse.persistence.moxy [2.7.12 -> 5.0.0-B03]
     http://www.eclipse.org/eclipselink
 - org.glassfish.jaxb:jaxb-core [2.3.0.1 -> 4.0.5]
     https://eclipse-ee4j.github.io/jaxb-ri/
 - org.glassfish.jaxb:jaxb-runtime [2.3.8 -> 4.0.5]
     https://eclipse-ee4j.github.io/jaxb-ri/
 - org.glassfish.jaxb:jaxb-xjc [2.3.8 -> 4.0.5]
     https://eclipse-ee4j.github.io/jaxb-ri/
 - org.glassfish.jersey.containers:jersey-container-jetty-http [3.1.3 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.glassfish.jersey.containers:jersey-container-servlet [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.glassfish.jersey.containers:jersey-container-servlet-core [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.glassfish.jersey.core:jersey-server [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.glassfish.jersey.inject:jersey-hk2 [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.glassfish.jersey.media:jersey-media-multipart [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.jetbrains.kotlin:kotlin-stdlib [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jetbrains.kotlin:kotlin-stdlib-jdk7 [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jetbrains.kotlin:kotlin-stdlib-jdk8 [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jfree:org.jfree.svg [4.1 -> 5.0.6]
     http://www.jfree.org/jfreesvg
 - org.junit.jupiter:junit-jupiter-api [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.jupiter:junit-jupiter-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.jupiter:junit-jupiter-params [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.vintage:junit-vintage-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.jvnet.jaxb2_commons:jaxb2-basics [0.13.1 -> 1.11.1]
     https://github.com/highsource/jaxb2-basics
 - org.jvnet.jaxb2_commons:jaxb2-basics-ant [0.13.1 -> 1.11.1]
     https://github.com/highsource/jaxb2-basics
 - org.jvnet.jaxb2_commons:jaxb2-basics-runtime [0.13.1 -> 2.0.12]
     https://github.com/highsource/jaxb-tools
 - org.mockito:mockito-core [5.13.0 -> 5.14.2]
     https://github.com/mockito/mockito
 - org.owasp.dependencycheck:org.owasp.dependencycheck.gradle.plugin [10.0.2 -> 10.0.4]
 - org.redisson:redisson [3.18.0 -> 3.37.0]
     http://redisson.org
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\build\dependencyUpdates\report.txt

> Task :wres-config:dependencyUpdates

------------------------------------------------------------
:wres-config Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - com.google.jimfs:jimfs:1.3.0
 - com.hubspot.jackson:jackson-datatype-protobuf:0.9.15
 - com.opencsv:opencsv:5.9
 - commons-beanutils:commons-beanutils:1.9.4
 - org.apache.commons:commons-lang3:3.17.0
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.jvnet.jaxb2_commons:jaxb2-basics-annotate:1.1.0
 - org.locationtech.jts:jts-core:1.20.0
 - org.locationtech.jts:jts-io:1.20.0

The following dependencies have later milestone versions:
 - ch.qos.logback:logback-classic [1.5.8 -> 1.5.11]
     http://logback.qos.ch
 - com.fasterxml.jackson:jackson-bom [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson-bom
 - com.fasterxml.jackson.core:jackson-annotations [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson
 - com.fasterxml.jackson.core:jackson-core [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson-core
 - com.fasterxml.jackson.core:jackson-databind [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson
 - com.fasterxml.jackson.dataformat:jackson-dataformat-yaml [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson-dataformats-text
 - com.fasterxml.jackson.datatype:jackson-datatype-jsr310 [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson-modules-java8
 - com.github.sabomichal:immutable-xjc-plugin [1.7.1 -> 2.0.3]
     https://github.com/sabomichal/immutable-xjc
 - com.google.guava:guava [33.3.0-jre -> 33.3.1-jre]
     https://github.com/google/guava
 - com.google.protobuf:protobuf-java [3.21.12 -> 4.29.0-RC1]
     https://developers.google.com/protocol-buffers/
 - com.google.protobuf:protobuf-java-util [3.21.12 -> 4.29.0-RC1]
     https://developers.google.com/protocol-buffers/
 - com.networknt:json-schema-validator [1.5.1 -> 1.5.2]
     https://github.com/networknt/json-schema-validator
 - commons-io:commons-io [2.16.1 -> 2.17.0]
     https://commons.apache.org/proper/commons-io/
 - io.soabase.record-builder:record-builder-core [41 -> 43]
     https://github.com/randgalt/record-builder
 - io.soabase.record-builder:record-builder-processor [41 -> 43]
     https://github.com/randgalt/record-builder
 - jakarta.activation:jakarta.activation-api [1.2.2 -> 2.1.3]
     https://github.com/jakartaee/jaf-api
 - jakarta.xml.bind:jakarta.xml.bind-api [2.3.3 -> 4.0.2]
     https://github.com/jakartaee/jaxb-api
 - org.apache.tika:tika-core [2.9.2 -> 3.0.0-BETA2]
     https://tika.apache.org/
 - org.eclipse.persistence:org.eclipse.persistence.moxy [2.7.12 -> 5.0.0-B03]
     http://www.eclipse.org/eclipselink
 - org.glassfish.jaxb:jaxb-core [2.3.0.1 -> 4.0.5]
     https://eclipse-ee4j.github.io/jaxb-ri/
 - org.glassfish.jaxb:jaxb-runtime [2.3.8 -> 4.0.5]
     https://eclipse-ee4j.github.io/jaxb-ri/
 - org.glassfish.jaxb:jaxb-xjc [2.3.8 -> 4.0.5]
     https://eclipse-ee4j.github.io/jaxb-ri/
 - org.junit.jupiter:junit-jupiter-api [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.jupiter:junit-jupiter-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.jupiter:junit-jupiter-params [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.jvnet.jaxb2_commons:jaxb2-basics [0.13.1 -> 1.11.1]
     https://github.com/highsource/jaxb2-basics
 - org.jvnet.jaxb2_commons:jaxb2-basics-ant [0.13.1 -> 1.11.1]
     https://github.com/highsource/jaxb2-basics
 - org.jvnet.jaxb2_commons:jaxb2-basics-runtime [0.13.1 -> 2.0.12]
     https://github.com/highsource/jaxb-tools
 - org.mockito:mockito-core [5.13.0 -> 5.14.2]
     https://github.com/mockito/mockito
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-config\build\dependencyUpdates\report.txt

> Task :wres-datamodel:dependencyUpdates

------------------------------------------------------------
:wres-datamodel Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - com.github.ben-manes.caffeine:caffeine:3.1.8
 - javax.measure:unit-api:2.2
 - junit:junit:4.13.2
 - org.apache.commons:commons-lang3:3.17.0
 - org.apache.commons:commons-math3:3.6.1
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.locationtech.jts:jts-core:1.20.0
 - si.uom:si-units:2.1
 - systems.uom:systems-quantity:2.1
 - systems.uom:systems-ucum:2.1
 - tech.units:indriya:2.2

The following dependencies have later milestone versions:
 - ch.qos.logback:logback-classic [1.5.8 -> 1.5.11]
     http://logback.qos.ch
 - org.junit.jupiter:junit-jupiter-api [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.jupiter:junit-jupiter-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.vintage:junit-vintage-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.mockito:mockito-core [5.13.0 -> 5.14.2]
     https://github.com/mockito/mockito
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-datamodel\build\dependencyUpdates\report.txt

> Task :wres-events:dependencyUpdates

------------------------------------------------------------
:wres-events Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - com.github.ben-manes.caffeine:caffeine:3.1.8
 - jakarta.jms:jakarta.jms-api:3.1.0
 - org.apache.commons:commons-lang3:3.17.0
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.mockito:mockito-inline:5.2.0

The following dependencies have later milestone versions:
 - ch.qos.logback:logback-classic [1.5.8 -> 1.5.11]
     http://logback.qos.ch
 - io.netty:netty-all [4.1.111.Final -> 5.0.0.Alpha2]
     http://netty.io/
 - org.apache.qpid:qpid-jms-client [2.5.0 -> 2.6.1]
     https://qpid.apache.org
 - org.junit.jupiter:junit-jupiter-api [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.jupiter:junit-jupiter-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.mockito:mockito-core [5.13.0 -> 5.14.2]
     https://github.com/mockito/mockito
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-events\build\dependencyUpdates\report.txt

> Task :wres-eventsbroker:dependencyUpdates

------------------------------------------------------------
:wres-eventsbroker Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - jakarta.jms:jakarta.jms-api:3.1.0
 - org.apache.activemq:artemis-amqp-protocol:2.37.0
 - org.apache.activemq:artemis-server:2.37.0
 - org.apache.commons:commons-configuration2:2.11.0
 - org.apache.commons:commons-lang3:3.17.0
 - org.bouncycastle:bcprov-jdk18on:1.78.1
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.slf4j:jcl-over-slf4j:2.1.0-alpha1

The following dependencies have later milestone versions:
 - ch.qos.logback:logback-classic [1.5.8 -> 1.5.11]
     http://logback.qos.ch
 - com.google.guava:guava [33.3.0-jre -> 33.3.1-jre]
     https://github.com/google/guava
 - org.apache.qpid:qpid-jms-client [2.5.0 -> 2.6.1]
     https://qpid.apache.org
 - org.junit.jupiter:junit-jupiter-api [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.jupiter:junit-jupiter-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-eventsbroker\build\dependencyUpdates\report.txt

> Task :wres-external-services-tests:dependencyUpdates

------------------------------------------------------------
:wres-external-services-tests Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-external-services-tests\build\dependencyUpdates\report.txt

> Task :wres-http:dependencyUpdates

------------------------------------------------------------
:wres-http Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - org.apache.commons:commons-lang3:3.17.0
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.mockito:mockito-inline:5.2.0

The following dependencies have later milestone versions:
 - com.squareup.okhttp3:okhttp [4.12.0 -> 5.0.0-alpha.14]
     https://square.github.io/okhttp/
 - org.jetbrains.kotlin:kotlin-stdlib [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jetbrains.kotlin:kotlin-stdlib-jdk7 [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jetbrains.kotlin:kotlin-stdlib-jdk8 [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.junit.jupiter:junit-jupiter-api [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.jupiter:junit-jupiter-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-http\build\dependencyUpdates\report.txt

> Task :wres-io:dependencyUpdates

------------------------------------------------------------
:wres-io Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - com.github.ben-manes.caffeine:caffeine:3.1.8
 - com.github.marschall:jfr-jdbc:0.4.0
 - com.google.jimfs:jimfs:1.3.0
 - com.h2database:h2:2.3.232
 - com.mattbertolini:liquibase-slf4j:5.0.0
 - junit:junit:4.13.2
 - org.glassfish:javax.json:1.1.4
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.liquibase:liquibase-core:4.29.2
 - org.locationtech.jts:jts-core:1.20.0
 - org.locationtech.jts:jts-io:1.20.0
 - org.mockito:mockito-inline:5.2.0
 - org.postgresql:postgresql:42.7.4
 - org.slf4j:jcl-over-slf4j:2.1.0-alpha1
 - org.slf4j:jul-to-slf4j:2.1.0-alpha1

The following dependencies have later milestone versions:
 - com.google.guava:guava [33.3.0-jre -> 33.3.1-jre]
     https://github.com/google/guava
 - com.google.guava:guava-testlib [33.3.0-jre -> 33.3.1-jre]
     https://github.com/google/guava
 - com.squareup.okhttp3:okhttp [4.12.0 -> 5.0.0-alpha.14]
     https://square.github.io/okhttp/
 - com.zaxxer:HikariCP [5.1.0 -> 6.0.0]
     https://github.com/brettwooldridge/HikariCP
 - edu.ucar:cdm-core [5.4.2 -> 6.0.0-beta1]
 - org.junit.jupiter:junit-jupiter-api [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.jupiter:junit-jupiter-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.vintage:junit-vintage-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-io\build\dependencyUpdates\report.txt

> Task :wres-messages:dependencyUpdates

------------------------------------------------------------
:wres-messages Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - junit:junit:4.13.2
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8

The following dependencies have later milestone versions:
 - com.google.protobuf:protobuf-java [3.21.12 -> 4.29.0-RC1]
     https://developers.google.com/protocol-buffers/
 - com.google.protobuf:protoc [3.21.12 -> 21.0-rc-1]
     https://developers.google.com/protocol-buffers/
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-messages\build\dependencyUpdates\report.txt

> Task :wres-metrics:dependencyUpdates

------------------------------------------------------------
:wres-metrics Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - junit:junit:4.13.2
 - org.apache.commons:commons-math3:3.6.1
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8

The following dependencies have later milestone versions:
 - ch.qos.logback:logback-classic [1.5.8 -> 1.5.11]
     http://logback.qos.ch
 - org.eclipse.collections:eclipse-collections [11.1.0 -> 12.0.0.M3]
     https://github.com/eclipse/eclipse-collections
 - org.junit.jupiter:junit-jupiter-api [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.jupiter:junit-jupiter-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.vintage:junit-vintage-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.mockito:mockito-core [5.13.0 -> 5.14.2]
     https://github.com/mockito/mockito
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-metrics\build\dependencyUpdates\report.txt

> Task :wres-reading:dependencyUpdates

------------------------------------------------------------
:wres-reading Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - com.google.jimfs:jimfs:1.3.0
 - com.mattbertolini:liquibase-slf4j:5.0.0
 - com.sun.xml.fastinfoset:FastInfoset:2.1.1
 - junit:junit:4.13.2
 - org.apache.commons:commons-compress:1.27.1
 - org.apache.commons:commons-math3:3.6.1
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.liquibase:liquibase-core:4.29.2
 - org.locationtech.jts:jts-core:1.20.0
 - org.locationtech.jts:jts-io:1.20.0
 - org.mock-server:mockserver-netty:5.15.0
 - org.mockito:mockito-inline:5.2.0
 - org.projectlombok:lombok:1.18.34

The following dependencies have later milestone versions:
 - com.fasterxml.jackson.datatype:jackson-datatype-jsr310 [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson-modules-java8
 - com.google.guava:guava [33.3.0-jre -> 33.3.1-jre]
     https://github.com/google/guava
 - com.google.guava:guava-testlib [33.3.0-jre -> 33.3.1-jre]
     https://github.com/google/guava
 - com.squareup.okhttp3:okhttp [4.12.0 -> 5.0.0-alpha.14]
     https://square.github.io/okhttp/
 - edu.ucar:cdm-core [5.4.2 -> 6.0.0-beta1]
 - org.apache.commons:commons-collections4 [4.4 -> 4.5.0-M2]
     https://commons.apache.org/proper/commons-collections/
 - org.apache.tika:tika-core [2.9.2 -> 3.0.0-BETA2]
     https://tika.apache.org/
 - org.junit.jupiter:junit-jupiter-api [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.jupiter:junit-jupiter-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.vintage:junit-vintage-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-reading\build\dependencyUpdates\report.txt

> Task :wres-statistics:dependencyUpdates

------------------------------------------------------------
:wres-statistics Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8

The following dependencies have later milestone versions:
 - ch.qos.logback:logback-classic [1.5.8 -> 1.5.11]
     http://logback.qos.ch
 - com.google.protobuf:protobuf-java [3.21.12 -> 4.29.0-RC1]
     https://developers.google.com/protocol-buffers/
 - com.google.protobuf:protoc [3.21.12 -> 21.0-rc-1]
     https://developers.google.com/protocol-buffers/
 - org.junit.jupiter:junit-jupiter-api [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.jupiter:junit-jupiter-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-statistics\build\dependencyUpdates\report.txt

> Task :wres-system:dependencyUpdates

------------------------------------------------------------
:wres-system Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - com.github.marschall:jfr-jdbc:0.4.0
 - com.h2database:h2:2.3.232
 - com.sun.xml.fastinfoset:FastInfoset:2.1.1
 - junit:junit:4.13.2
 - org.apache.commons:commons-lang3:3.17.0
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.mock-server:mockserver-netty:5.15.0
 - org.postgresql:postgresql:42.7.4
 - org.projectlombok:lombok:1.18.34
 - org.slf4j:jul-to-slf4j:2.1.0-alpha1

The following dependencies have later milestone versions:
 - com.zaxxer:HikariCP [5.1.0 -> 6.0.0]
     https://github.com/brettwooldridge/HikariCP
 - jakarta.xml.bind:jakarta.xml.bind-api [2.3.3 -> 4.0.2]
     https://github.com/jakartaee/jaxb-api
 - org.jvnet.jaxb2_commons:jaxb2-basics-runtime [0.13.1 -> 2.0.12]
     https://github.com/highsource/jaxb-tools
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-system\build\dependencyUpdates\report.txt

> Task :wres-tasker:dependencyUpdates

------------------------------------------------------------
:wres-tasker Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - com.github.ben-manes.caffeine:caffeine:3.1.8
 - com.google.jimfs:jimfs:1.3.0
 - commons-codec:commons-codec:1.17.1
 - io.swagger.core.v3:swagger-jaxrs2:2.2.23
 - javax.servlet:javax.servlet-api:3.1.0
 - javax.ws.rs:javax.ws.rs-api:2.1
 - junit:junit:4.13.2
 - org.apache.commons:commons-lang3:3.17.0
 - org.apache.qpid:qpid-broker-core:9.2.0
 - org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol:9.2.0
 - org.apache.qpid:qpid-broker-plugins-memory-store:9.2.0
 - org.bouncycastle:bcpkix-jdk18on:1.78.1
 - org.bouncycastle:bcprov-jdk18on:1.78.1
 - org.eclipse.jetty:jetty-webapp:11.0.24
 - org.eclipse.jetty.http2:http2-server:11.0.24
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8

The following dependencies have later milestone versions:
 - ch.qos.logback:logback-classic [1.5.8 -> 1.5.11]
     http://logback.qos.ch
 - com.fasterxml.jackson:jackson-bom [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson-bom
 - com.fasterxml.jackson.core:jackson-annotations [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson
 - com.fasterxml.jackson.core:jackson-core [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson-core
 - com.fasterxml.jackson.core:jackson-databind [2.17.2 -> 2.18.0]
     https://github.com/FasterXML/jackson
 - com.google.protobuf:protobuf-java [3.21.12 -> 4.29.0-RC1]
     https://developers.google.com/protocol-buffers/
 - com.rabbitmq:amqp-client [5.21.0 -> 5.22.0]
     https://www.rabbitmq.com
 - com.squareup.okhttp3:okhttp [4.12.0 -> 5.0.0-alpha.14]
     https://square.github.io/okhttp/
 - io.netty:netty-all [4.1.111.Final -> 5.0.0.Alpha2]
     http://netty.io/
 - io.swagger.core.v3:swagger-jaxrs2-jakarta [2.2.23 -> 2.2.25]
     https://github.com/swagger-api/swagger-core
 - jakarta.annotation:jakarta.annotation-api [2.1.1 -> 3.0.0]
     https://projects.eclipse.org/projects/ee4j.ca
 - jakarta.ws.rs:jakarta.ws.rs-api [3.1.0 -> 4.0.0]
     https://github.com/jakartaee/rest
 - org.apache.commons:commons-lang3 [3.12.0 -> 3.17.0]
     https://commons.apache.org/proper/commons-lang/
 - org.apache.tika:tika-core [2.9.2 -> 3.0.0-BETA2]
     https://tika.apache.org/
 - org.eclipse.jetty:jetty-alpn-java-server [11.0.24 -> 12.0.14]
     https://jetty.org
 - org.eclipse.jetty:jetty-server [11.0.24 -> 12.0.14]
     https://jetty.org
 - org.glassfish.jersey.containers:jersey-container-servlet-core [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.glassfish.jersey.core:jersey-server [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.glassfish.jersey.inject:jersey-hk2 [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.glassfish.jersey.media:jersey-media-multipart [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.jetbrains.kotlin:kotlin-stdlib [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jetbrains.kotlin:kotlin-stdlib-jdk7 [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jetbrains.kotlin:kotlin-stdlib-jdk8 [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.junit.jupiter:junit-jupiter-api [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.jupiter:junit-jupiter-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.vintage:junit-vintage-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.redisson:redisson [3.18.0 -> 3.37.0]
     http://redisson.org
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-tasker\build\dependencyUpdates\report.txt

> Task :wres-vis:dependencyUpdates

------------------------------------------------------------
:wres-vis Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - com.google.jimfs:jimfs:1.3.0
 - com.sun.xml.fastinfoset:FastInfoset:2.1.1
 - junit:junit:4.13.2
 - org.apache.commons:commons-lang3:3.17.0
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.jfree:jfreechart:1.5.5
 - org.slf4j:log4j-over-slf4j:2.1.0-alpha1

The following dependencies have later milestone versions:
 - ch.qos.logback:logback-classic [1.5.8 -> 1.5.11]
     http://logback.qos.ch
 - org.jfree:org.jfree.svg [4.1 -> 5.0.6]
     http://www.jfree.org/jfreesvg
 - org.junit.jupiter:junit-jupiter-api [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.jupiter:junit-jupiter-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.vintage:junit-vintage-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.mockito:mockito-core [5.13.0 -> 5.14.2]
     https://github.com/mockito/mockito
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-vis\build\dependencyUpdates\report.txt

> Task :wres-worker:dependencyUpdates

------------------------------------------------------------
:wres-worker Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - junit:junit:4.13.2
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.mock-server:mockserver-netty:5.15.0
 - org.mockito:mockito-inline:5.2.0

The following dependencies have later milestone versions:
 - ch.qos.logback:logback-classic [1.5.8 -> 1.5.11]
     http://logback.qos.ch
 - com.rabbitmq:amqp-client [5.21.0 -> 5.22.0]
     https://www.rabbitmq.com
 - com.squareup.okhttp3:okhttp [4.12.0 -> 5.0.0-alpha.14]
     https://square.github.io/okhttp/
 - jakarta.ws.rs:jakarta.ws.rs-api [3.1.0 -> 4.0.0]
     https://github.com/jakartaee/rest
 - org.junit.jupiter:junit-jupiter-api [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.jupiter:junit-jupiter-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-worker\build\dependencyUpdates\report.txt

> Task :wres-writing:dependencyUpdates

------------------------------------------------------------
:wres-writing Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - com.google.jimfs:jimfs:1.3.0
 - junit:junit:4.13.2
 - org.apache.commons:commons-math3:3.6.1
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.locationtech.jts:jts-core:1.20.0
 - org.locationtech.jts:jts-io:1.20.0
 - org.mockito:mockito-inline:5.2.0

The following dependencies have later milestone versions:
 - com.google.guava:guava [33.3.0-jre -> 33.3.1-jre]
     https://github.com/google/guava
 - com.squareup.okhttp3:okhttp [4.12.0 -> 5.0.0-alpha.14]
     https://square.github.io/okhttp/
 - edu.ucar:cdm-core [5.4.2 -> 6.0.0-beta1]
 - org.apache.tika:tika-core [2.9.2 -> 3.0.0-BETA2]
     https://tika.apache.org/
 - org.jetbrains.kotlin:kotlin-stdlib [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jetbrains.kotlin:kotlin-stdlib-jdk7 [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jetbrains.kotlin:kotlin-stdlib-jdk8 [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.junit.jupiter:junit-jupiter-api [5.11.0 -> 5.11.2]
     https://junit.org/junit5/
 - org.junit.jupiter:junit-jupiter-engine [5.11.0 -> 5.11.2]
     https://junit.org/junit5/

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-writing\build\dependencyUpdates\report.txt

Deprecated Gradle features were used in this build, making it incompatible with Gradle 8.0.

You can use '--warning-mode all' to show the individual deprecation warnings and determine if they come from your own scripts or plugins.

See https://docs.gradle.org/7.6.4/userguide/command_line_interface.html#sec:command_line_warnings

BUILD SUCCESSFUL in 28s
17 actionable tasks: 17 executed
epag commented 1 month ago

After updates


> Configure project :
20241017-b2d7094
20241017-b2d7094

> Task :dependencyUpdates

------------------------------------------------------------
: Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - ch.qos.logback:logback-classic:1.5.11
 - com.adarshr.test-logger:com.adarshr.test-logger.gradle.plugin:4.0.0
 - com.atlassian.commonmark:commonmark:0.17.0
 - com.fasterxml.jackson:jackson-bom:2.18.0
 - com.fasterxml.jackson.core:jackson-annotations:2.18.0
 - com.fasterxml.jackson.core:jackson-core:2.18.0
 - com.fasterxml.jackson.core:jackson-databind:2.18.0
 - com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.18.0
 - com.fasterxml.jackson.datatype:jackson-datatype-jsr310:2.18.0
 - com.github.ben-manes.caffeine:caffeine:3.1.8
 - com.github.ben-manes.versions:com.github.ben-manes.versions.gradle.plugin:0.51.0
 - com.github.marschall:jfr-jdbc:0.4.0
 - com.github.seanrl.jaxb:com.github.seanrl.jaxb.gradle.plugin:2.5.4
 - com.google.guava:guava:33.3.1-jre
 - com.google.guava:guava-testlib:33.3.1-jre
 - com.google.jimfs:jimfs:1.3.0
 - com.h2database:h2:2.3.232
 - com.hubspot.jackson:jackson-datatype-protobuf:0.9.15
 - com.mattbertolini:liquibase-slf4j:5.0.0
 - com.netflix.nebula:gradle-aggregate-javadocs-plugin:3.0.1
 - com.networknt:json-schema-validator:1.5.2
 - com.opencsv:opencsv:5.9
 - com.rabbitmq:amqp-client:5.22.0
 - com.sun.xml.fastinfoset:FastInfoset:2.1.1
 - commons-beanutils:commons-beanutils:1.9.4
 - commons-codec:commons-codec:1.17.1
 - commons-io:commons-io:2.17.0
 - de.undercouch.download:de.undercouch.download.gradle.plugin:5.6.0
 - io.swagger.core.v3:swagger-jaxrs2:2.2.25
 - io.swagger.core.v3:swagger-jaxrs2-jakarta:2.2.25
 - io.swagger.core.v3.swagger-gradle-plugin:io.swagger.core.v3.swagger-gradle-plugin.gradle.plugin:2.2.25
 - jakarta.jms:jakarta.jms-api:3.1.0
 - javax.measure:unit-api:2.2
 - javax.servlet:javax.servlet-api:3.1.0
 - javax.ws.rs:javax.ws.rs-api:2.1
 - junit:junit:4.13.2
 - org.ajoberstar.grgit:org.ajoberstar.grgit.gradle.plugin:5.3.0
 - org.apache.activemq:artemis-amqp-protocol:2.37.0
 - org.apache.activemq:artemis-server:2.37.0
 - org.apache.commons:commons-compress:1.27.1
 - org.apache.commons:commons-configuration2:2.11.0
 - org.apache.commons:commons-lang3:3.17.0
 - org.apache.commons:commons-math3:3.6.1
 - org.apache.qpid:qpid-broker-core:9.2.0
 - org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol:9.2.0
 - org.apache.qpid:qpid-broker-plugins-memory-store:9.2.0
 - org.apache.qpid:qpid-jms-client:2.6.1
 - org.bouncycastle:bcpkix-jdk18on:1.78.1
 - org.bouncycastle:bcprov-jdk18on:1.78.1
 - org.eclipse.jetty:jetty-webapp:11.0.24
 - org.eclipse.jetty.http2:http2-server:11.0.24
 - org.glassfish:javax.json:1.1.4
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.jfree:jfreechart:1.5.5
 - org.junit.jupiter:junit-jupiter-api:5.11.2
 - org.junit.jupiter:junit-jupiter-engine:5.11.2
 - org.junit.jupiter:junit-jupiter-params:5.11.2
 - org.junit.vintage:junit-vintage-engine:5.11.2
 - org.jvnet.jaxb2_commons:jaxb2-basics-annotate:1.1.0
 - org.kordamp.gradle.markdown:org.kordamp.gradle.markdown.gradle.plugin:2.2.0
 - org.liquibase:liquibase-core:4.29.2
 - org.locationtech.jts:jts-core:1.20.0
 - org.locationtech.jts:jts-io:1.20.0
 - org.mock-server:mockserver-netty:5.15.0
 - org.mockito:mockito-core:5.14.2
 - org.mockito:mockito-inline:5.2.0
 - org.owasp.dependencycheck:org.owasp.dependencycheck.gradle.plugin:10.0.4
 - org.postgresql:postgresql:42.7.4
 - org.projectlombok:lombok:1.18.34
 - org.slf4j:jcl-over-slf4j:2.1.0-alpha1
 - org.slf4j:jul-to-slf4j:2.1.0-alpha1
 - org.slf4j:log4j-over-slf4j:2.1.0-alpha1
 - org.sonarqube:org.sonarqube.gradle.plugin:5.1.0.4882
 - si.uom:si-units:2.1
 - systems.uom:systems-quantity:2.1
 - systems.uom:systems-ucum:2.1
 - tech.units:indriya:2.2

The following dependencies have later milestone versions:
 - com.github.sabomichal:immutable-xjc-plugin [1.7.1 -> 2.0.3]
     https://github.com/sabomichal/immutable-xjc
 - com.google.protobuf:com.google.protobuf.gradle.plugin [0.9.1 -> 0.9.4]
 - com.google.protobuf:protobuf-java [3.21.12 -> 4.29.0-RC1]
     https://developers.google.com/protocol-buffers/
 - com.google.protobuf:protobuf-java-util [3.21.12 -> 4.29.0-RC1]
     https://developers.google.com/protocol-buffers/
 - com.google.protobuf:protoc [3.21.12 -> 21.0-rc-1]
     https://developers.google.com/protocol-buffers/
 - com.squareup.okhttp3:okhttp [4.12.0 -> 5.0.0-alpha.14]
     https://square.github.io/okhttp/
 - com.zaxxer:HikariCP [5.1.0 -> 6.0.0]
     https://github.com/brettwooldridge/HikariCP
 - edu.ucar:cdm-core [5.4.2 -> 6.0.0-beta1]
 - io.netty:netty-all [4.1.111.Final -> 5.0.0.Alpha2]
     http://netty.io/
 - io.soabase.record-builder:record-builder-core [41 -> 43]
     https://github.com/randgalt/record-builder
 - io.soabase.record-builder:record-builder-processor [41 -> 43]
     https://github.com/randgalt/record-builder
 - jakarta.activation:jakarta.activation-api [1.2.2 -> 2.1.3]
     https://github.com/jakartaee/jaf-api
 - jakarta.annotation:jakarta.annotation-api [2.1.1 -> 3.0.0]
     https://projects.eclipse.org/projects/ee4j.ca
 - jakarta.ws.rs:jakarta.ws.rs-api [3.1.0 -> 4.0.0]
     https://github.com/jakartaee/rest
 - jakarta.xml.bind:jakarta.xml.bind-api [2.3.3 -> 4.0.2]
     https://github.com/jakartaee/jaxb-api
 - jakarta.xml.bind:jakarta.xml.bind-api [3.0.1 -> 4.0.2]
     https://github.com/jakartaee/jaxb-api
 - org.apache.commons:commons-collections4 [4.4 -> 4.5.0-M2]
     https://commons.apache.org/proper/commons-collections/
 - org.apache.commons:commons-lang3 [3.12.0 -> 3.17.0]
     https://commons.apache.org/proper/commons-lang/
 - org.apache.tika:tika-core [2.9.2 -> 3.0.0-BETA2]
     https://tika.apache.org/
 - org.beryx.jlink:org.beryx.jlink.gradle.plugin [2.26.0 -> 3.0.1]
 - org.eclipse.collections:eclipse-collections [11.1.0 -> 12.0.0.M3]
     https://github.com/eclipse/eclipse-collections
 - org.eclipse.jetty:jetty-alpn-java-server [11.0.24 -> 12.0.14]
     https://jetty.org
 - org.eclipse.jetty:jetty-server [11.0.24 -> 12.0.14]
     https://jetty.org
 - org.eclipse.persistence:org.eclipse.persistence.moxy [2.7.12 -> 5.0.0-B03]
     http://www.eclipse.org/eclipselink
 - org.glassfish.jaxb:jaxb-core [2.3.0.1 -> 4.0.5]
     https://eclipse-ee4j.github.io/jaxb-ri/
 - org.glassfish.jaxb:jaxb-runtime [2.3.8 -> 4.0.5]
     https://eclipse-ee4j.github.io/jaxb-ri/
 - org.glassfish.jaxb:jaxb-xjc [2.3.8 -> 4.0.5]
     https://eclipse-ee4j.github.io/jaxb-ri/
 - org.glassfish.jersey.containers:jersey-container-jetty-http [3.1.3 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.glassfish.jersey.containers:jersey-container-servlet [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.glassfish.jersey.containers:jersey-container-servlet-core [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.glassfish.jersey.core:jersey-server [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.glassfish.jersey.inject:jersey-hk2 [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.glassfish.jersey.media:jersey-media-multipart [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.jetbrains.kotlin:kotlin-stdlib [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jetbrains.kotlin:kotlin-stdlib-jdk7 [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jetbrains.kotlin:kotlin-stdlib-jdk8 [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jfree:org.jfree.svg [4.1 -> 5.0.6]
     http://www.jfree.org/jfreesvg
 - org.jvnet.jaxb2_commons:jaxb2-basics [0.13.1 -> 1.11.1]
     https://github.com/highsource/jaxb2-basics
 - org.jvnet.jaxb2_commons:jaxb2-basics-ant [0.13.1 -> 1.11.1]
     https://github.com/highsource/jaxb2-basics
 - org.jvnet.jaxb2_commons:jaxb2-basics-runtime [0.13.1 -> 2.0.12]
     https://github.com/highsource/jaxb-tools
 - org.redisson:redisson [3.18.0 -> 3.37.0]
     http://redisson.org
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\build\dependencyUpdates\report.txt

> Task :wres-config:dependencyUpdates

------------------------------------------------------------
:wres-config Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - ch.qos.logback:logback-classic:1.5.11
 - com.fasterxml.jackson:jackson-bom:2.18.0
 - com.fasterxml.jackson.core:jackson-annotations:2.18.0
 - com.fasterxml.jackson.core:jackson-core:2.18.0
 - com.fasterxml.jackson.core:jackson-databind:2.18.0
 - com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.18.0
 - com.fasterxml.jackson.datatype:jackson-datatype-jsr310:2.18.0
 - com.google.guava:guava:33.3.1-jre
 - com.google.jimfs:jimfs:1.3.0
 - com.hubspot.jackson:jackson-datatype-protobuf:0.9.15
 - com.networknt:json-schema-validator:1.5.2
 - com.opencsv:opencsv:5.9
 - commons-beanutils:commons-beanutils:1.9.4
 - commons-io:commons-io:2.17.0
 - org.apache.commons:commons-lang3:3.17.0
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.junit.jupiter:junit-jupiter-api:5.11.2
 - org.junit.jupiter:junit-jupiter-engine:5.11.2
 - org.junit.jupiter:junit-jupiter-params:5.11.2
 - org.jvnet.jaxb2_commons:jaxb2-basics-annotate:1.1.0
 - org.locationtech.jts:jts-core:1.20.0
 - org.locationtech.jts:jts-io:1.20.0
 - org.mockito:mockito-core:5.14.2

The following dependencies have later milestone versions:
 - com.github.sabomichal:immutable-xjc-plugin [1.7.1 -> 2.0.3]
     https://github.com/sabomichal/immutable-xjc
 - com.google.protobuf:protobuf-java [3.21.12 -> 4.29.0-RC1]
     https://developers.google.com/protocol-buffers/
 - com.google.protobuf:protobuf-java-util [3.21.12 -> 4.29.0-RC1]
     https://developers.google.com/protocol-buffers/
 - io.soabase.record-builder:record-builder-core [41 -> 43]
     https://github.com/randgalt/record-builder
 - io.soabase.record-builder:record-builder-processor [41 -> 43]
     https://github.com/randgalt/record-builder
 - jakarta.activation:jakarta.activation-api [1.2.2 -> 2.1.3]
     https://github.com/jakartaee/jaf-api
 - jakarta.xml.bind:jakarta.xml.bind-api [2.3.3 -> 4.0.2]
     https://github.com/jakartaee/jaxb-api
 - org.apache.tika:tika-core [2.9.2 -> 3.0.0-BETA2]
     https://tika.apache.org/
 - org.eclipse.persistence:org.eclipse.persistence.moxy [2.7.12 -> 5.0.0-B03]
     http://www.eclipse.org/eclipselink
 - org.glassfish.jaxb:jaxb-core [2.3.0.1 -> 4.0.5]
     https://eclipse-ee4j.github.io/jaxb-ri/
 - org.glassfish.jaxb:jaxb-runtime [2.3.8 -> 4.0.5]
     https://eclipse-ee4j.github.io/jaxb-ri/
 - org.glassfish.jaxb:jaxb-xjc [2.3.8 -> 4.0.5]
     https://eclipse-ee4j.github.io/jaxb-ri/
 - org.jvnet.jaxb2_commons:jaxb2-basics [0.13.1 -> 1.11.1]
     https://github.com/highsource/jaxb2-basics
 - org.jvnet.jaxb2_commons:jaxb2-basics-ant [0.13.1 -> 1.11.1]
     https://github.com/highsource/jaxb2-basics
 - org.jvnet.jaxb2_commons:jaxb2-basics-runtime [0.13.1 -> 2.0.12]
     https://github.com/highsource/jaxb-tools
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-config\build\dependencyUpdates\report.txt

> Task :wres-datamodel:dependencyUpdates

------------------------------------------------------------
:wres-datamodel Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - ch.qos.logback:logback-classic:1.5.11
 - com.github.ben-manes.caffeine:caffeine:3.1.8
 - javax.measure:unit-api:2.2
 - junit:junit:4.13.2
 - org.apache.commons:commons-lang3:3.17.0
 - org.apache.commons:commons-math3:3.6.1
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.junit.jupiter:junit-jupiter-api:5.11.2
 - org.junit.jupiter:junit-jupiter-engine:5.11.2
 - org.junit.vintage:junit-vintage-engine:5.11.2
 - org.locationtech.jts:jts-core:1.20.0
 - org.mockito:mockito-core:5.14.2
 - si.uom:si-units:2.1
 - systems.uom:systems-quantity:2.1
 - systems.uom:systems-ucum:2.1
 - tech.units:indriya:2.2

The following dependencies have later milestone versions:
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-datamodel\build\dependencyUpdates\report.txt

> Task :wres-events:dependencyUpdates

------------------------------------------------------------
:wres-events Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - ch.qos.logback:logback-classic:1.5.11
 - com.github.ben-manes.caffeine:caffeine:3.1.8
 - jakarta.jms:jakarta.jms-api:3.1.0
 - org.apache.commons:commons-lang3:3.17.0
 - org.apache.qpid:qpid-jms-client:2.6.1
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.junit.jupiter:junit-jupiter-api:5.11.2
 - org.junit.jupiter:junit-jupiter-engine:5.11.2
 - org.mockito:mockito-core:5.14.2
 - org.mockito:mockito-inline:5.2.0

The following dependencies have later milestone versions:
 - io.netty:netty-all [4.1.111.Final -> 5.0.0.Alpha2]
     http://netty.io/
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-events\build\dependencyUpdates\report.txt

> Task :wres-eventsbroker:dependencyUpdates

------------------------------------------------------------
:wres-eventsbroker Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - ch.qos.logback:logback-classic:1.5.11
 - com.google.guava:guava:33.3.1-jre
 - jakarta.jms:jakarta.jms-api:3.1.0
 - org.apache.activemq:artemis-amqp-protocol:2.37.0
 - org.apache.activemq:artemis-server:2.37.0
 - org.apache.commons:commons-configuration2:2.11.0
 - org.apache.commons:commons-lang3:3.17.0
 - org.apache.qpid:qpid-jms-client:2.6.1
 - org.bouncycastle:bcprov-jdk18on:1.78.1
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.junit.jupiter:junit-jupiter-api:5.11.2
 - org.junit.jupiter:junit-jupiter-engine:5.11.2
 - org.slf4j:jcl-over-slf4j:2.1.0-alpha1

The following dependencies have later milestone versions:
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-eventsbroker\build\dependencyUpdates\report.txt

> Task :wres-external-services-tests:dependencyUpdates

------------------------------------------------------------
:wres-external-services-tests Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-external-services-tests\build\dependencyUpdates\report.txt

> Task :wres-http:dependencyUpdates

------------------------------------------------------------
:wres-http Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - org.apache.commons:commons-lang3:3.17.0
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.junit.jupiter:junit-jupiter-api:5.11.2
 - org.junit.jupiter:junit-jupiter-engine:5.11.2
 - org.mockito:mockito-inline:5.2.0

The following dependencies have later milestone versions:
 - com.squareup.okhttp3:okhttp [4.12.0 -> 5.0.0-alpha.14]
     https://square.github.io/okhttp/
 - org.jetbrains.kotlin:kotlin-stdlib [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jetbrains.kotlin:kotlin-stdlib-jdk7 [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jetbrains.kotlin:kotlin-stdlib-jdk8 [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-http\build\dependencyUpdates\report.txt

> Task :wres-io:dependencyUpdates

------------------------------------------------------------
:wres-io Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - com.github.ben-manes.caffeine:caffeine:3.1.8
 - com.github.marschall:jfr-jdbc:0.4.0
 - com.google.guava:guava:33.3.1-jre
 - com.google.guava:guava-testlib:33.3.1-jre
 - com.google.jimfs:jimfs:1.3.0
 - com.h2database:h2:2.3.232
 - com.mattbertolini:liquibase-slf4j:5.0.0
 - junit:junit:4.13.2
 - org.glassfish:javax.json:1.1.4
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.junit.jupiter:junit-jupiter-api:5.11.2
 - org.junit.jupiter:junit-jupiter-engine:5.11.2
 - org.junit.vintage:junit-vintage-engine:5.11.2
 - org.liquibase:liquibase-core:4.29.2
 - org.locationtech.jts:jts-core:1.20.0
 - org.locationtech.jts:jts-io:1.20.0
 - org.mockito:mockito-inline:5.2.0
 - org.postgresql:postgresql:42.7.4
 - org.slf4j:jcl-over-slf4j:2.1.0-alpha1
 - org.slf4j:jul-to-slf4j:2.1.0-alpha1

The following dependencies have later milestone versions:
 - com.squareup.okhttp3:okhttp [4.12.0 -> 5.0.0-alpha.14]
     https://square.github.io/okhttp/
 - com.zaxxer:HikariCP [5.1.0 -> 6.0.0]
     https://github.com/brettwooldridge/HikariCP
 - edu.ucar:cdm-core [5.4.2 -> 6.0.0-beta1]

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-io\build\dependencyUpdates\report.txt

> Task :wres-messages:dependencyUpdates

------------------------------------------------------------
:wres-messages Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - junit:junit:4.13.2
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8

The following dependencies have later milestone versions:
 - com.google.protobuf:protobuf-java [3.21.12 -> 4.29.0-RC1]
     https://developers.google.com/protocol-buffers/
 - com.google.protobuf:protoc [3.21.12 -> 21.0-rc-1]
     https://developers.google.com/protocol-buffers/
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-messages\build\dependencyUpdates\report.txt

> Task :wres-metrics:dependencyUpdates

------------------------------------------------------------
:wres-metrics Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - ch.qos.logback:logback-classic:1.5.11
 - junit:junit:4.13.2
 - org.apache.commons:commons-math3:3.6.1
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.junit.jupiter:junit-jupiter-api:5.11.2
 - org.junit.jupiter:junit-jupiter-engine:5.11.2
 - org.junit.vintage:junit-vintage-engine:5.11.2
 - org.mockito:mockito-core:5.14.2

The following dependencies have later milestone versions:
 - org.eclipse.collections:eclipse-collections [11.1.0 -> 12.0.0.M3]
     https://github.com/eclipse/eclipse-collections
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-metrics\build\dependencyUpdates\report.txt

> Task :wres-reading:dependencyUpdates

------------------------------------------------------------
:wres-reading Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - com.fasterxml.jackson.datatype:jackson-datatype-jsr310:2.18.0
 - com.google.guava:guava:33.3.1-jre
 - com.google.guava:guava-testlib:33.3.1-jre
 - com.google.jimfs:jimfs:1.3.0
 - com.mattbertolini:liquibase-slf4j:5.0.0
 - com.sun.xml.fastinfoset:FastInfoset:2.1.1
 - junit:junit:4.13.2
 - org.apache.commons:commons-compress:1.27.1
 - org.apache.commons:commons-math3:3.6.1
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.junit.jupiter:junit-jupiter-api:5.11.2
 - org.junit.jupiter:junit-jupiter-engine:5.11.2
 - org.junit.vintage:junit-vintage-engine:5.11.2
 - org.liquibase:liquibase-core:4.29.2
 - org.locationtech.jts:jts-core:1.20.0
 - org.locationtech.jts:jts-io:1.20.0
 - org.mock-server:mockserver-netty:5.15.0
 - org.mockito:mockito-inline:5.2.0
 - org.projectlombok:lombok:1.18.34

The following dependencies have later milestone versions:
 - com.squareup.okhttp3:okhttp [4.12.0 -> 5.0.0-alpha.14]
     https://square.github.io/okhttp/
 - edu.ucar:cdm-core [5.4.2 -> 6.0.0-beta1]
 - org.apache.commons:commons-collections4 [4.4 -> 4.5.0-M2]
     https://commons.apache.org/proper/commons-collections/
 - org.apache.tika:tika-core [2.9.2 -> 3.0.0-BETA2]
     https://tika.apache.org/

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-reading\build\dependencyUpdates\report.txt

> Task :wres-statistics:dependencyUpdates

------------------------------------------------------------
:wres-statistics Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - ch.qos.logback:logback-classic:1.5.11
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.junit.jupiter:junit-jupiter-api:5.11.2
 - org.junit.jupiter:junit-jupiter-engine:5.11.2

The following dependencies have later milestone versions:
 - com.google.protobuf:protobuf-java [3.21.12 -> 4.29.0-RC1]
     https://developers.google.com/protocol-buffers/
 - com.google.protobuf:protoc [3.21.12 -> 21.0-rc-1]
     https://developers.google.com/protocol-buffers/
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-statistics\build\dependencyUpdates\report.txt

> Task :wres-system:dependencyUpdates

------------------------------------------------------------
:wres-system Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - com.github.marschall:jfr-jdbc:0.4.0
 - com.h2database:h2:2.3.232
 - com.sun.xml.fastinfoset:FastInfoset:2.1.1
 - junit:junit:4.13.2
 - org.apache.commons:commons-lang3:3.17.0
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.mock-server:mockserver-netty:5.15.0
 - org.postgresql:postgresql:42.7.4
 - org.projectlombok:lombok:1.18.34
 - org.slf4j:jul-to-slf4j:2.1.0-alpha1

The following dependencies have later milestone versions:
 - com.zaxxer:HikariCP [5.1.0 -> 6.0.0]
     https://github.com/brettwooldridge/HikariCP
 - jakarta.xml.bind:jakarta.xml.bind-api [2.3.3 -> 4.0.2]
     https://github.com/jakartaee/jaxb-api
 - org.jvnet.jaxb2_commons:jaxb2-basics-runtime [0.13.1 -> 2.0.12]
     https://github.com/highsource/jaxb-tools
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-system\build\dependencyUpdates\report.txt

> Task :wres-tasker:dependencyUpdates

------------------------------------------------------------
:wres-tasker Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - ch.qos.logback:logback-classic:1.5.11
 - com.fasterxml.jackson:jackson-bom:2.18.0
 - com.fasterxml.jackson.core:jackson-annotations:2.18.0
 - com.fasterxml.jackson.core:jackson-core:2.18.0
 - com.fasterxml.jackson.core:jackson-databind:2.18.0
 - com.github.ben-manes.caffeine:caffeine:3.1.8
 - com.google.jimfs:jimfs:1.3.0
 - com.rabbitmq:amqp-client:5.22.0
 - commons-codec:commons-codec:1.17.1
 - io.swagger.core.v3:swagger-jaxrs2:2.2.25
 - io.swagger.core.v3:swagger-jaxrs2-jakarta:2.2.25
 - javax.servlet:javax.servlet-api:3.1.0
 - javax.ws.rs:javax.ws.rs-api:2.1
 - junit:junit:4.13.2
 - org.apache.commons:commons-lang3:3.17.0
 - org.apache.qpid:qpid-broker-core:9.2.0
 - org.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol:9.2.0
 - org.apache.qpid:qpid-broker-plugins-memory-store:9.2.0
 - org.bouncycastle:bcpkix-jdk18on:1.78.1
 - org.bouncycastle:bcprov-jdk18on:1.78.1
 - org.eclipse.jetty:jetty-webapp:11.0.24
 - org.eclipse.jetty.http2:http2-server:11.0.24
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.junit.jupiter:junit-jupiter-api:5.11.2
 - org.junit.jupiter:junit-jupiter-engine:5.11.2
 - org.junit.vintage:junit-vintage-engine:5.11.2

The following dependencies have later milestone versions:
 - com.google.protobuf:protobuf-java [3.21.12 -> 4.29.0-RC1]
     https://developers.google.com/protocol-buffers/
 - com.squareup.okhttp3:okhttp [4.12.0 -> 5.0.0-alpha.14]
     https://square.github.io/okhttp/
 - io.netty:netty-all [4.1.111.Final -> 5.0.0.Alpha2]
     http://netty.io/
 - jakarta.annotation:jakarta.annotation-api [2.1.1 -> 3.0.0]
     https://projects.eclipse.org/projects/ee4j.ca
 - jakarta.ws.rs:jakarta.ws.rs-api [3.1.0 -> 4.0.0]
     https://github.com/jakartaee/rest
 - org.apache.commons:commons-lang3 [3.12.0 -> 3.17.0]
     https://commons.apache.org/proper/commons-lang/
 - org.apache.tika:tika-core [2.9.2 -> 3.0.0-BETA2]
     https://tika.apache.org/
 - org.eclipse.jetty:jetty-alpn-java-server [11.0.24 -> 12.0.14]
     https://jetty.org
 - org.eclipse.jetty:jetty-server [11.0.24 -> 12.0.14]
     https://jetty.org
 - org.glassfish.jersey.containers:jersey-container-servlet-core [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.glassfish.jersey.core:jersey-server [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.glassfish.jersey.inject:jersey-hk2 [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.glassfish.jersey.media:jersey-media-multipart [3.1.8 -> 4.0.0-M1]
     https://projects.eclipse.org/projects/ee4j.jersey
 - org.jetbrains.kotlin:kotlin-stdlib [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jetbrains.kotlin:kotlin-stdlib-jdk7 [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jetbrains.kotlin:kotlin-stdlib-jdk8 [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.redisson:redisson [3.18.0 -> 3.37.0]
     http://redisson.org
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-tasker\build\dependencyUpdates\report.txt

> Task :wres-vis:dependencyUpdates

------------------------------------------------------------
:wres-vis Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - ch.qos.logback:logback-classic:1.5.11
 - com.google.jimfs:jimfs:1.3.0
 - com.sun.xml.fastinfoset:FastInfoset:2.1.1
 - junit:junit:4.13.2
 - org.apache.commons:commons-lang3:3.17.0
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.jfree:jfreechart:1.5.5
 - org.junit.jupiter:junit-jupiter-api:5.11.2
 - org.junit.jupiter:junit-jupiter-engine:5.11.2
 - org.junit.vintage:junit-vintage-engine:5.11.2
 - org.mockito:mockito-core:5.14.2
 - org.slf4j:log4j-over-slf4j:2.1.0-alpha1

The following dependencies have later milestone versions:
 - org.jfree:org.jfree.svg [4.1 -> 5.0.6]
     http://www.jfree.org/jfreesvg
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-vis\build\dependencyUpdates\report.txt

> Task :wres-worker:dependencyUpdates

------------------------------------------------------------
:wres-worker Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - ch.qos.logback:logback-classic:1.5.11
 - com.rabbitmq:amqp-client:5.22.0
 - junit:junit:4.13.2
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.junit.jupiter:junit-jupiter-api:5.11.2
 - org.junit.jupiter:junit-jupiter-engine:5.11.2
 - org.mock-server:mockserver-netty:5.15.0
 - org.mockito:mockito-inline:5.2.0

The following dependencies have later milestone versions:
 - com.squareup.okhttp3:okhttp [4.12.0 -> 5.0.0-alpha.14]
     https://square.github.io/okhttp/
 - jakarta.ws.rs:jakarta.ws.rs-api [3.1.0 -> 4.0.0]
     https://github.com/jakartaee/rest
 - org.slf4j:slf4j-api [2.0.13 -> 2.1.0-alpha1]
     http://www.slf4j.org

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-worker\build\dependencyUpdates\report.txt

> Task :wres-writing:dependencyUpdates

------------------------------------------------------------
:wres-writing Project Dependency Updates (report to plain text file)
------------------------------------------------------------

The following dependencies are using the latest milestone version:
 - com.google.guava:guava:33.3.1-jre
 - com.google.jimfs:jimfs:1.3.0
 - junit:junit:4.13.2
 - org.apache.commons:commons-math3:3.6.1
 - org.jacoco:org.jacoco.agent:0.8.8
 - org.jacoco:org.jacoco.ant:0.8.8
 - org.junit.jupiter:junit-jupiter-api:5.11.2
 - org.junit.jupiter:junit-jupiter-engine:5.11.2
 - org.locationtech.jts:jts-core:1.20.0
 - org.locationtech.jts:jts-io:1.20.0
 - org.mockito:mockito-inline:5.2.0

The following dependencies have later milestone versions:
 - com.squareup.okhttp3:okhttp [4.12.0 -> 5.0.0-alpha.14]
     https://square.github.io/okhttp/
 - edu.ucar:cdm-core [5.4.2 -> 6.0.0-beta1]
 - org.apache.tika:tika-core [2.9.2 -> 3.0.0-BETA2]
     https://tika.apache.org/
 - org.jetbrains.kotlin:kotlin-stdlib [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jetbrains.kotlin:kotlin-stdlib-jdk7 [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/
 - org.jetbrains.kotlin:kotlin-stdlib-jdk8 [1.9.23 -> 2.1.0-Beta2]
     https://kotlinlang.org/

Failed to determine the latest version for the following dependencies (use --info for details):
 - net.jcip:jcip-annotations

Gradle release-candidate updates:
 - Gradle: [7.6.4 -> 8.10.2 -> 8.11-rc-1]

Generated report file C:\Users\epagr\IdeaProjects\wres\wres-writing\build\dependencyUpdates\report.txt

Deprecated Gradle features were used in this build, making it incompatible with Gradle 8.0.

You can use '--warning-mode all' to show the individual deprecation warnings and determine if they come from your own scripts or plugins.

See https://docs.gradle.org/7.6.4/userguide/command_line_interface.html#sec:command_line_warnings

BUILD SUCCESSFUL in 8s
17 actionable tasks: 17 executed
epag commented 1 month ago

When attempting to run the vuln check I am getting this odd error:

> Task :dependencyCheckAnalyze FAILED
Verifying dependencies for project wres

FAILURE: Build failed with an exception.

* What went wrong:
Execution failed for task ':dependencyCheckAnalyze'.
> Class org.gradle.api.internal.artifacts.configurations.DefaultConfiguration_Decorated does not implement the requested interface org.gradle.api.Named
epag commented 1 month ago

Looks like the issue came from me bumping this:

    id 'org.owasp.dependencycheck' version '10.0.2'

Seems like we are stuck at 10.0.2 for the time being

epag commented 1 month ago

Here are the vulnerabilities scan results, looking at these now:

> Configure project :
20241017-b2d7094-dev
20241017-b2d7094-dev

> Task :dependencyCheckAnalyze FAILED
Verifying dependencies for project wres

Deprecated Gradle features were used in this build, making it incompatible with Gradle 8.0.

You can use '--warning-mode all' to show the individual deprecation warnings and determine if they come from your own scripts or plugins.

See https://docs.gradle.org/7.6.4/userguide/command_line_interface.html#sec:command_line_warnings
1 actionable task: 1 executed

> Configure project :
20241017-b2d7094-dev
20241017-b2d7094-dev

> Task :dependencyCheckAnalyze
Could not register JMX bean.

Verifying dependencies for project wres
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres
Found 9 vulnerabilities in project wres

One or more dependencies were identified with known vulnerabilities in wres:

h2-2.3.232.jar (pkg:maven/com.h2database/h2@2.3.232, cpe:2.3:a:h2database:h2:2.3.232:*:*:*:*:*:*:*) : CVE-2018-14335
jackson-databind-2.13.4.2.jar (pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.13.4.2, cpe:2.3:a:fasterxml:jackson-databind:2.13.4.2:*:*:*:*:*:*:*) : CVE-2023-35116
javax.json-1.1.4.jar (pkg:maven/org.glassfish/javax.json@1.1.4) : CVE-2023-7272
jetty-http-11.0.24.jar (pkg:maven/org.eclipse.jetty/jetty-http@11.0.24, cpe:2.3:a:eclipse:jetty:11.0.24:*:*:*:*:*:*:*, cpe:2.3:a:jetty:jetty:11.0.24:*:*:*:*:*:*:*, cpe:2.3:a:mortbay_jetty:jetty:11.0.24:*:*:*:*:*:*:*) : CVE-2024-6763
jodd-bean-5.1.6.jar (pkg:maven/org.jodd/jodd-bean@5.1.6, cpe:2.3:a:jodd:jodd:5.1.6:*:*:*:*:*:*:*, cpe:2.3:a:jodd:jodd_http:5.1.6:*:*:*:*:*:*:*) : CVE-2022-29631
jodd-core-5.1.6.jar (pkg:maven/org.jodd/jodd-core@5.1.6, cpe:2.3:a:jodd:jodd:5.1.6:*:*:*:*:*:*:*, cpe:2.3:a:jodd:jodd_http:5.1.6:*:*:*:*:*:*:*) : CVE-2022-29631
protobuf-java-3.21.12.jar (pkg:maven/com.google.protobuf/protobuf-java@3.21.12, cpe:2.3:a:google:protobuf-java:3.21.12:*:*:*:*:*:*:*, cpe:2.3:a:protobuf:protobuf:3.21.12:*:*:*:*:*:*:*) : CVE-2024-7254
redisson-3.18.0.jar (pkg:maven/org.redisson/redisson@3.18.0, cpe:2.3:a:redisson:redisson:3.18.0:*:*:*:*:*:*:*) : CVE-2023-42809
snakeyaml-1.33.jar (pkg:maven/org.yaml/snakeyaml@1.33, cpe:2.3:a:snakeyaml_project:snakeyaml:1.33:*:*:*:*:*:*:*) : CVE-2022-1471

See the dependency-check report for more details.

> Task :wres-config:dependencyCheckAnalyze
Could not register JMX bean.

Verifying dependencies for project wres-config
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres-config
Found 1 vulnerabilities in project wres-config

One or more dependencies were identified with known vulnerabilities in wres-config:

protobuf-java-3.21.12.jar (pkg:maven/com.google.protobuf/protobuf-java@3.21.12, cpe:2.3:a:google:protobuf-java:3.21.12:*:*:*:*:*:*:*, cpe:2.3:a:protobuf:protobuf:3.21.12:*:*:*:*:*:*:*) : CVE-2024-7254

See the dependency-check report for more details.

> Task :wres-datamodel:dependencyCheckAnalyze
Could not register JMX bean.

Verifying dependencies for project wres-datamodel
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres-datamodel
Found 1 vulnerabilities in project wres-datamodel

One or more dependencies were identified with known vulnerabilities in wres-datamodel:

protobuf-java-3.21.12.jar (pkg:maven/com.google.protobuf/protobuf-java@3.21.12, cpe:2.3:a:google:protobuf-java:3.21.12:*:*:*:*:*:*:*, cpe:2.3:a:protobuf:protobuf:3.21.12:*:*:*:*:*:*:*) : CVE-2024-7254

See the dependency-check report for more details.

> Task :wres-events:dependencyCheckAnalyze
Could not register JMX bean.

Verifying dependencies for project wres-events
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres-events
Found 1 vulnerabilities in project wres-events

One or more dependencies were identified with known vulnerabilities in wres-events:

protobuf-java-3.21.12.jar (pkg:maven/com.google.protobuf/protobuf-java@3.21.12, cpe:2.3:a:google:protobuf-java:3.21.12:*:*:*:*:*:*:*, cpe:2.3:a:protobuf:protobuf:3.21.12:*:*:*:*:*:*:*) : CVE-2024-7254

See the dependency-check report for more details.

> Task :wres-eventsbroker:dependencyCheckAnalyze
Could not register JMX bean.

Verifying dependencies for project wres-eventsbroker
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres-eventsbroker
Found 0 vulnerabilities in project wres-eventsbroker

> Task :wres-external-services-tests:dependencyCheckAnalyze
Could not register JMX bean.
Verifying dependencies for project wres-external-services-tests
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres-external-services-tests
Found 2 vulnerabilities in project wres-external-services-tests

One or more dependencies were identified with known vulnerabilities in wres-external-services-tests:

h2-2.3.232.jar (pkg:maven/com.h2database/h2@2.3.232, cpe:2.3:a:h2database:h2:2.3.232:*:*:*:*:*:*:*) : CVE-2018-14335
protobuf-java-3.21.12.jar (pkg:maven/com.google.protobuf/protobuf-java@3.21.12, cpe:2.3:a:google:protobuf-java:3.21.12:*:*:*:*:*:*:*, cpe:2.3:a:protobuf:protobuf:3.21.12:*:*:*:*:*:*:*) : CVE-2024-7254

See the dependency-check report for more details.

> Task :wres-http:dependencyCheckAnalyze
Could not register JMX bean.

Verifying dependencies for project wres-http
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres-http
Found 0 vulnerabilities in project wres-http

> Task :wres-io:dependencyCheckAnalyze
Could not register JMX bean.

Verifying dependencies for project wres-io
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres-io
Found 3 vulnerabilities in project wres-io

One or more dependencies were identified with known vulnerabilities in wres-io:

h2-2.3.232.jar (pkg:maven/com.h2database/h2@2.3.232, cpe:2.3:a:h2database:h2:2.3.232:*:*:*:*:*:*:*) : CVE-2018-14335
javax.json-1.1.4.jar (pkg:maven/org.glassfish/javax.json@1.1.4) : CVE-2023-7272
protobuf-java-3.21.12.jar (pkg:maven/com.google.protobuf/protobuf-java@3.21.12, cpe:2.3:a:google:protobuf-java:3.21.12:*:*:*:*:*:*:*, cpe:2.3:a:protobuf:protobuf:3.21.12:*:*:*:*:*:*:*) : CVE-2024-7254

See the dependency-check report for more details.

> Task :wres-messages:dependencyCheckAnalyze
Could not register JMX bean.

Verifying dependencies for project wres-messages
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres-messages
Found 1 vulnerabilities in project wres-messages

One or more dependencies were identified with known vulnerabilities in wres-messages:

protobuf-java-3.21.12.jar (pkg:maven/com.google.protobuf/protobuf-java@3.21.12, cpe:2.3:a:google:protobuf-java:3.21.12:*:*:*:*:*:*:*, cpe:2.3:a:protobuf:protobuf:3.21.12:*:*:*:*:*:*:*) : CVE-2024-7254

See the dependency-check report for more details.

> Task :wres-metrics:dependencyCheckAnalyze
Could not register JMX bean.

Verifying dependencies for project wres-metrics
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres-metrics
Found 1 vulnerabilities in project wres-metrics

One or more dependencies were identified with known vulnerabilities in wres-metrics:

protobuf-java-3.21.12.jar (pkg:maven/com.google.protobuf/protobuf-java@3.21.12, cpe:2.3:a:google:protobuf-java:3.21.12:*:*:*:*:*:*:*, cpe:2.3:a:protobuf:protobuf:3.21.12:*:*:*:*:*:*:*) : CVE-2024-7254

See the dependency-check report for more details.

> Task :wres-reading:dependencyCheckAnalyze
Could not register JMX bean.

Verifying dependencies for project wres-reading
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres-reading
Found 2 vulnerabilities in project wres-reading

One or more dependencies were identified with known vulnerabilities in wres-reading:

h2-2.3.232.jar (pkg:maven/com.h2database/h2@2.3.232, cpe:2.3:a:h2database:h2:2.3.232:*:*:*:*:*:*:*) : CVE-2018-14335
protobuf-java-3.21.12.jar (pkg:maven/com.google.protobuf/protobuf-java@3.21.12, cpe:2.3:a:google:protobuf-java:3.21.12:*:*:*:*:*:*:*, cpe:2.3:a:protobuf:protobuf:3.21.12:*:*:*:*:*:*:*) : CVE-2024-7254

See the dependency-check report for more details.

> Task :wres-statistics:dependencyCheckAnalyze
Could not register JMX bean.

Verifying dependencies for project wres-statistics
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres-statistics
Found 1 vulnerabilities in project wres-statistics

One or more dependencies were identified with known vulnerabilities in wres-statistics:

protobuf-java-3.21.12.jar (pkg:maven/com.google.protobuf/protobuf-java@3.21.12, cpe:2.3:a:google:protobuf-java:3.21.12:*:*:*:*:*:*:*, cpe:2.3:a:protobuf:protobuf:3.21.12:*:*:*:*:*:*:*) : CVE-2024-7254

See the dependency-check report for more details.

> Task :wres-system:dependencyCheckAnalyze
Could not register JMX bean.

Verifying dependencies for project wres-system
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres-system
Found 1 vulnerabilities in project wres-system

One or more dependencies were identified with known vulnerabilities in wres-system:

h2-2.3.232.jar (pkg:maven/com.h2database/h2@2.3.232, cpe:2.3:a:h2database:h2:2.3.232:*:*:*:*:*:*:*) : CVE-2018-14335

See the dependency-check report for more details.

> Task :wres-tasker:dependencyCheckAnalyze
Could not register JMX bean.

Verifying dependencies for project wres-tasker
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres-tasker
Found 5 vulnerabilities in project wres-tasker

One or more dependencies were identified with known vulnerabilities in wres-tasker:

jetty-http-11.0.24.jar (pkg:maven/org.eclipse.jetty/jetty-http@11.0.24, cpe:2.3:a:eclipse:jetty:11.0.24:*:*:*:*:*:*:*, cpe:2.3:a:jetty:jetty:11.0.24:*:*:*:*:*:*:*, cpe:2.3:a:mortbay_jetty:jetty:11.0.24:*:*:*:*:*:*:*) : CVE-2024-6763
jodd-bean-5.1.6.jar (pkg:maven/org.jodd/jodd-bean@5.1.6, cpe:2.3:a:jodd:jodd:5.1.6:*:*:*:*:*:*:*, cpe:2.3:a:jodd:jodd_http:5.1.6:*:*:*:*:*:*:*) : CVE-2022-29631
jodd-core-5.1.6.jar (pkg:maven/org.jodd/jodd-core@5.1.6, cpe:2.3:a:jodd:jodd:5.1.6:*:*:*:*:*:*:*, cpe:2.3:a:jodd:jodd_http:5.1.6:*:*:*:*:*:*:*) : CVE-2022-29631
protobuf-java-3.21.12.jar (pkg:maven/com.google.protobuf/protobuf-java@3.21.12, cpe:2.3:a:google:protobuf-java:3.21.12:*:*:*:*:*:*:*, cpe:2.3:a:protobuf:protobuf:3.21.12:*:*:*:*:*:*:*) : CVE-2024-7254
redisson-3.18.0.jar (pkg:maven/org.redisson/redisson@3.18.0, cpe:2.3:a:redisson:redisson:3.18.0:*:*:*:*:*:*:*) : CVE-2023-42809

See the dependency-check report for more details.

> Task :wres-vis:dependencyCheckAnalyze
Could not register JMX bean.

Verifying dependencies for project wres-vis
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres-vis
Found 1 vulnerabilities in project wres-vis

One or more dependencies were identified with known vulnerabilities in wres-vis:

protobuf-java-3.21.12.jar (pkg:maven/com.google.protobuf/protobuf-java@3.21.12, cpe:2.3:a:google:protobuf-java:3.21.12:*:*:*:*:*:*:*, cpe:2.3:a:protobuf:protobuf:3.21.12:*:*:*:*:*:*:*) : CVE-2024-7254

See the dependency-check report for more details.

> Task :wres-worker:dependencyCheckAnalyze
Could not register JMX bean.

Verifying dependencies for project wres-worker
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres-worker
Found 1 vulnerabilities in project wres-worker

One or more dependencies were identified with known vulnerabilities in wres-worker:

protobuf-java-3.21.12.jar (pkg:maven/com.google.protobuf/protobuf-java@3.21.12, cpe:2.3:a:google:protobuf-java:3.21.12:*:*:*:*:*:*:*, cpe:2.3:a:protobuf:protobuf:3.21.12:*:*:*:*:*:*:*) : CVE-2024-7254

See the dependency-check report for more details.

> Task :wres-writing:dependencyCheckAnalyze
Could not register JMX bean.

Verifying dependencies for project wres-writing
Checking for updates and analyzing dependencies for vulnerabilities
Generating report for project wres-writing
Found 2 vulnerabilities in project wres-writing

One or more dependencies were identified with known vulnerabilities in wres-writing:

h2-2.3.232.jar (pkg:maven/com.h2database/h2@2.3.232, cpe:2.3:a:h2database:h2:2.3.232:*:*:*:*:*:*:*) : CVE-2018-14335
protobuf-java-3.21.12.jar (pkg:maven/com.google.protobuf/protobuf-java@3.21.12, cpe:2.3:a:google:protobuf-java:3.21.12:*:*:*:*:*:*:*, cpe:2.3:a:protobuf:protobuf:3.21.12:*:*:*:*:*:*:*) : CVE-2024-7254

See the dependency-check report for more details.

Deprecated Gradle features were used in this build, making it incompatible with Gradle 8.0.

You can use '--warning-mode all' to show the individual deprecation warnings and determine if they come from your own scripts or plugins.

See https://docs.gradle.org/7.6.4/userguide/command_line_interface.html#sec:command_line_warnings

BUILD SUCCESSFUL in 43s
17 actionable tasks: 17 executed
epag commented 1 month ago

Looks like the only new one of interest is this protobuff one but based on the link it doesnt seem like there is a version that resolves it and we also are currently blocked on upgrading our protobuff version anyways I think. https://nvd.nist.gov/vuln/detail/CVE-2024-7254

Looks like everyhthing else is the same or a false alarm

james-d-brown commented 1 month ago

Not sure that is correct, see below:

https://github.com/advisories/GHSA-735f-pc8j-v9w8

james-d-brown commented 1 month ago

But it would mean updating to 3.25.5, which may be blocked by other things that we now need to resolve urgently, so I would check those other things again.

epag commented 1 month ago

Ah gotcha, thanks for the other link. Ill look into bumping it tomorrow, but I recall the protobuff stuff being blocked from bumping for quite awhile so this deploy may be delayed

epag commented 1 month ago

Alright good news, protobuf version 3.25.5 seems to have both removed the issue noted in #70 and one of the few versions not affected by the CVE above.

epag commented 1 month ago

Jetty version is current highest

epag commented 1 month ago

rabbitmq, reddis, artemis at latest