Skip to content

Commit 2fe2c3d

Browse files
Manage transitive dependencies version for security updates
Some of transitive dependencies can be managed to newer versions. Added: - commons-beanutils - commons-codec - commons-io - dom4j - plexus-archiver
1 parent 1130350 commit 2fe2c3d

File tree

3 files changed

+49
-6
lines changed

3 files changed

+49
-6
lines changed

pom.xml

Lines changed: 49 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -137,7 +137,6 @@
137137
<scmpublish.content>${project.build.directory}/staging/versions</scmpublish.content>
138138
<!-- mono-module doesn't require site:stage for scm-publish -->
139139
<project.build.outputTimestamp>2022-12-15T11:58:30Z</project.build.outputTimestamp>
140-
<sisu-maven-plugin-version>0.9.0.M1</sisu-maven-plugin-version>
141140
</properties>
142141

143142
<dependencyManagement>
@@ -195,6 +194,29 @@
195194
<artifactId>maven-reporting-impl</artifactId>
196195
<version>3.2.0</version>
197196
</dependency>
197+
198+
<dependency>
199+
<groupId>org.apache.maven.doxia</groupId>
200+
<artifactId>doxia-core</artifactId>
201+
<version>${doxiaVersion}</version>
202+
</dependency>
203+
<dependency>
204+
<groupId>org.apache.maven.doxia</groupId>
205+
<artifactId>doxia-sink-api</artifactId>
206+
<version>${doxiaVersion}</version>
207+
</dependency>
208+
209+
<dependency>
210+
<groupId>org.apache.maven.doxia</groupId>
211+
<artifactId>doxia-site-renderer</artifactId>
212+
<version>${doxia-sitetoolsVersion}</version>
213+
</dependency>
214+
<dependency>
215+
<groupId>org.apache.maven.doxia</groupId>
216+
<artifactId>doxia-integration-tools</artifactId>
217+
<version>${doxia-sitetoolsVersion}</version>
218+
</dependency>
219+
198220
<dependency>
199221
<groupId>org.apache.maven.shared</groupId>
200222
<artifactId>maven-common-artifact-filters</artifactId>
@@ -255,6 +277,32 @@
255277
<scope>import</scope>
256278
</dependency>
257279

280+
<!-- manage transitive dependencies due to security patches -->
281+
<dependency>
282+
<groupId>commons-beanutils</groupId>
283+
<artifactId>commons-beanutils</artifactId>
284+
<version>1.9.4</version>
285+
</dependency>
286+
<dependency>
287+
<groupId>commons-codec</groupId>
288+
<artifactId>commons-codec</artifactId>
289+
<version>1.15</version>
290+
</dependency>
291+
<dependency>
292+
<groupId>commons-io</groupId>
293+
<artifactId>commons-io</artifactId>
294+
<version>2.11.0</version>
295+
</dependency>
296+
<dependency>
297+
<groupId>dom4j</groupId>
298+
<artifactId>dom4j</artifactId>
299+
<version>1.6.1</version>
300+
</dependency>
301+
<dependency>
302+
<groupId>org.codehaus.plexus</groupId>
303+
<artifactId>plexus-archiver</artifactId>
304+
<version>4.6.0</version>
305+
</dependency>
258306
</dependencies>
259307
</dependencyManagement>
260308

versions-maven-plugin/pom.xml

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -84,19 +84,16 @@
8484
<dependency>
8585
<groupId>org.apache.maven.doxia</groupId>
8686
<artifactId>doxia-core</artifactId>
87-
<version>${doxiaVersion}</version>
8887
</dependency>
8988
<dependency>
9089
<groupId>org.apache.maven.doxia</groupId>
9190
<artifactId>doxia-sink-api</artifactId>
92-
<version>${doxiaVersion}</version>
9391
</dependency>
9492

9593
<!-- Doxia-sitetools -->
9694
<dependency>
9795
<groupId>org.apache.maven.doxia</groupId>
9896
<artifactId>doxia-site-renderer</artifactId>
99-
<version>${doxia-sitetoolsVersion}</version>
10097
</dependency>
10198

10299
<dependency>

versions-test/pom.xml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -43,12 +43,10 @@
4343
<dependency>
4444
<groupId>org.apache.maven.doxia</groupId>
4545
<artifactId>doxia-integration-tools</artifactId>
46-
<version>${doxiaVersion}</version>
4746
</dependency>
4847
<dependency>
4948
<groupId>org.apache.maven.doxia</groupId>
5049
<artifactId>doxia-site-renderer</artifactId>
51-
<version>${doxia-sitetoolsVersion}</version>
5250
</dependency>
5351
<dependency>
5452
<groupId>org.codehaus.mojo.versions</groupId>

0 commit comments

Comments
 (0)