restlet / restlet-framework-java

The first REST API framework for Java
https://restlet.talend.com
649 stars 284 forks source link

Upgrade libraries to fix CVEs #1407

Closed thboileau closed 4 months ago

thboileau commented 8 months ago

Let's update the dependencies for the 2.4 version (future 2.5 will be handled differently)

cglib:cglib-nodep .............................................. 2.2.2 -> 3.3.0
com.fasterxml.jackson.core:jackson-annotations ................. 2.9.6 -> 2.16.1
com.fasterxml.jackson.core:jackson-core ........................ 2.9.6 -> 2.16.1
com.fasterxml.jackson.core:jackson-databind .................... 2.9.6 -> 2.16.1
com.fasterxml.jackson.dataformat:jackson-dataformat-csv ........ 2.9.6 -> 2.16.1
com.fasterxml.jackson.dataformat:jackson-dataformat-smile ...... 2.9.6 -> 2.16.1
com.fasterxml.jackson.dataformat:jackson-dataformat-xml ........ 2.9.6 -> 2.16.1
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml ....... 2.9.6 -> 2.16.1
com.fasterxml.jackson.module:jackson-module-jaxb-annotations ... 2.9.6 -> 2.16.1
com.fasterxml.jackson.module:jackson-module-jsonSchema ......... 2.9.6 -> 2.16.1
com.google.code.gson:gson ...................................... 2.3.1 -> 2.10.1
com.google.guava ............................................ 26.0-jre -> 33.1.0-jre
com.google.inject:guice .......................................... 3.0 -> 6.0.0
commons-codec:commons-codec ...................................... 1.5 -> 1.17.0
commons-collections:commons-collections ........................ 3.2.1 -> 3.2.2
commons-dbcp:commons-dbcp ........................................ 1.3 -> 1.4
commons-fileupload:commons-fileupload .......................... 1.3.3 -> 1.5
commons-io:commons-io ............................................ 2.6 -> 2.16.1
commons-logging:commons-logging ................................ 1.1.3 -> 1.3.1
commons-pool:commons-pool ...................................... 1.5.6 -> 1.6
com.sun.xml.bind:jaxb-impl .................................... 2.1.12 -> 2.3.9
javax.mail:mail ................................................ 1.4.2 -> 1.4.7
joda-time:joda-time .............................................. 2.3 -> 2.12.6
net.sourceforge.nekohtml:nekohtml ............................. 1.9.19 -> 1.9.22
org.apache.commons:commons-lang3 ................................. 3.6 -> 3.14.0
org.apache.httpcomponents:httpclient ........................... 4.5.6 -> 4.5.14
org.apache.httpcomponents:httpcore ............................ 4.4.10 -> 4.4.16
org.apache.httpcomponents:httpmime ............................. 4.5.6 -> 4.5.14
org.apache.james:apache-mime4j-core ............................ 0.7.2 -> 0.8.9
org.apache.lucene:lucene-core .................................. 4.6.0 -> 9.9.1
org.apache.solr:solr-core ...................................... 7.4.0 -> 8.11.2
org.apache.solr:solr-solrj ..................................... 7.4.0 -> 8.11.2
org.apache.tika:tika-core ....................................... 1.18 -> 1.28.5
org.apache.tika:tika-parsers .................................... 1.18 -> 1.28.5
org.apache.velocity:velocity-engine-core ......................... 2.0 -> 2.3
org.codehaus.woodstox:stax2-api ................................ 3.1.4 -> 4.2.2
org.codehaus.woodstox:woodstox-core-asl ........................ 4.3.0 -> 4.4.1
org.eclipse.emf.ecore.xmi ....................... 2.5.0.v20100521-1846 -> 2.35.0
org.eclipse.emf:org.eclipse.emf.common .......... 2.6.0.v20100614-1136 -> 2.29.0
org.eclipse.emf:org.eclipse.emf.core ............ 2.6.0.v20100614-1136 -> 2.35.0
org.eclipse.jetty:jetty-client ...................... 9.4.11.v20180605 -> 9.4.54.v20240208
org.eclipse.jetty:jetty-http ........................ 9.4.11.v20180605 -> 9.4.54.v20240208
org.eclipse.jetty:jetty-io .......................... 9.4.11.v20180605 -> 9.4.54.v20240208
org.eclipse.jetty:jetty-server ...................... 9.4.11.v20180605 -> 9.4.54.v20240208
org.eclipse.jetty:jetty-util ........................ 9.4.11.v20180605 -> 9.4.54.v20240208
org.freemarker:freemarker ..................................... 2.3.20 -> 2.3.32
org.jboss.resteasy:resteasy-jaxrs ........................ 3.6.0.Final -> 3.15.6.Final
org.json:json ............................................... 20160212 -> 20231013
org.raml:raml-parser ........................................... 0.8.7 -> 0.8.40
org.scala-lang:scala-library ................................... 2.9.1 -> 2.13.13
org.scala-lang:scalap .......................................... 2.9.1 -> 2.13.13
org.slf4j:slf4j-api ............................................ 1.7.2 -> 2.0.13
org.springframework ................................... 3.2.18.RELEASE -> 5.3.34
org.thymeleaf:thymeleaf ....................................... 2.3.20 -> 2.1.6.RELEASE
org.yaml:snakeyaml .............................................. 1.18 -> 2.2