vivo-project / VIVO

VIVO is an extensible semantic web application for research discovery and showcasing scholarly work
http://vivoweb.org
BSD 3-Clause "New" or "Revised" License
202 stars 127 forks source link

Update dependencies #3925

Open chenejac opened 7 months ago

chenejac commented 7 months ago

Describe the bug There might be some security vulnerabilities due to outdated libraries. Also, we should check whether we are using different versions of some libraries. Here is the VIVO dependency tree

Expected behavior We should update dependencies to a version without reported vulnerabilities at maven repository such as this one

litvinovg commented 7 months ago

At some point it would be useful to replace dependencies that we can easily replace with our own code. For example org.directwebremoting.dwr