micro-service that takes an XHTML document and produces a pdf document at various conformance levels. The main driver for this is to create a 'generic' pdf-generator but also to create PDFA/1A compliant documents for DRS. It has recently been extended to support the PDF/UA standard for accessibility and uses an(other) in-house service which has abstracted the pdf 'build' activities (https://github.com/dwp/html-to-pdf)
Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.
Changes included in this PR
Vulnerabilities that will be fixed
With an upgrade:
Why? Has a fix available, CVSS 5.5
SNYK-JAVA-COMGOOGLEGUAVA-1015415
io.dropwizard:dropwizard-client:
2.0.6 -> 2.0.16
io.dropwizard:dropwizard-core:
2.0.6 -> 2.0.21
Why? Has a fix available, CVSS 2.9
SNYK-JAVA-JUNIT-1017047
com.openhtmltopdf:openhtmltopdf-pdfbox:
1.0.0 -> 1.0.6
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
SNYK-JAVA-ORGECLIPSEJETTY-1090340
io.dropwizard:dropwizard-client:
2.0.6 -> 2.0.16
io.dropwizard:dropwizard-core:
2.0.6 -> 2.0.21
org.eclipse.jetty:jetty-security:
9.4.30.v20200611 -> 9.4.39.v20210325
org.eclipse.jetty:jetty-server:
9.4.30.v20200611 -> 9.4.39.v20210325
org.eclipse.jetty:jetty-servlets:
9.4.30.v20200611 -> 9.4.41.v20210516
org.eclipse.jetty:jetty-webapp:
9.4.30.v20200611 -> 9.4.39.v20210325
Why? Recently disclosed, Has a fix available, CVSS 5.3
SNYK-JAVA-ORGECLIPSEJETTY-1300835
org.eclipse.jetty:jetty-servlets:
9.4.30.v20200611 -> 9.4.41.v20210516
(*) Note that the real score may have changed since the PR was raised.
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information: 🧐 View latest project report
🛠 Adjust project settings
📚 Read more about Snyk's upgrade and patch logic