Skip to content

Commit ebff47b

Browse files
authored
Fix vulnerable deps (#391)
* fix some deps vulnerabilities * update agent config * fix guava version * fix jackson dep * use android version for guava * fix jackson ver * fix jackson ver * fix shaded protobuf version
1 parent 8f4d68c commit ebff47b

File tree

6 files changed

+6
-9
lines changed

6 files changed

+6
-9
lines changed

buildSrc/build.gradle.kts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@ dependencies {
3636
implementation("org.eclipse.aether", "aether-transport-http", "1.1.0")
3737
implementation("org.apache.maven", "maven-aether-provider", "3.3.9")
3838

39-
implementation("com.google.guava", "guava", "20.0")
39+
implementation("com.google.guava", "guava", "32.0.0-android")
4040
implementation("org.ow2.asm", "asm", "9.1")
4141
implementation("org.ow2.asm", "asm-tree", "9.1")
4242
implementation("org.apache.httpcomponents:httpclient:4.5.10")

instrumentation/spark-2.3/build.gradle.kts

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -28,9 +28,6 @@ val versions: Map<String, String> by extra
2828
dependencies {
2929
api(project(":instrumentation:servlet:servlet-3.0"))
3030

31-
testImplementation("io.opentelemetry.javaagent.instrumentation:opentelemetry-javaagent-spark-2.3:${versions["opentelemetry_java_agent"]}")
32-
testImplementation("io.opentelemetry.javaagent.instrumentation:opentelemetry-javaagent-servlet-3.0:${versions["opentelemetry_java_agent"]}")
33-
testImplementation("io.opentelemetry.javaagent.instrumentation:opentelemetry-javaagent-jetty-8.0:${versions["opentelemetry_java_agent"]}")
3431
testRuntimeOnly("io.opentelemetry.javaagent.instrumentation:opentelemetry-javaagent-servlet-common-bootstrap:${versions["opentelemetry_java_agent"]}")
3532
muzzleBootstrap("io.opentelemetry.javaagent.instrumentation:opentelemetry-javaagent-servlet-common-bootstrap:${versions["opentelemetry_java_agent"]}")
3633

javaagent-core/build.gradle.kts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ dependencies {
99
api("io.opentelemetry:opentelemetry-api:${versions["opentelemetry"]}")
1010
api("io.opentelemetry.instrumentation:opentelemetry-instrumentation-api:${versions["opentelemetry"]}")
1111
implementation("org.slf4j:slf4j-api:${versions["slf4j"]}")
12-
implementation("com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.13.3") {
12+
implementation("com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.13.4") {
1313
constraints {
1414
implementation("org.yaml:snakeyaml:1.31") {
1515
because(

otel-extensions/build.gradle.kts

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ plugins {
77
}
88

99

10-
val protobufVersion = "3.16.1"
10+
val protobufVersion = "3.19.6"
1111

1212
protobuf {
1313
protoc {
@@ -59,7 +59,7 @@ dependencies {
5959
api("com.google.protobuf:protobuf-java")
6060
api("com.google.protobuf:protobuf-java-util")
6161
// convert yaml to json, since java protobuf impl supports only json
62-
implementation("com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.13.3") {
62+
implementation("com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.13.4") {
6363
constraints {
6464
implementation("org.yaml:snakeyaml:1.31") {
6565
because(

smoke-tests/build.gradle.kts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ dependencies{
2424
testImplementation("com.google.protobuf:protobuf-java-util:3.15.8")
2525
testImplementation("org.spockframework:spock-core:1.3-groovy-2.5")
2626
testImplementation("info.solidsoft.spock:spock-global-unroll:0.5.1")
27-
testImplementation("com.fasterxml.jackson.core:jackson-databind:2.11.2")
27+
testImplementation("com.fasterxml.jackson.core:jackson-databind:2.13.4")
2828
testImplementation("org.codehaus.groovy:groovy-all:2.5.11")
2929
testImplementation("io.opentelemetry:opentelemetry-semconv:${versions["opentelemetry"]}-alpha")
3030
}

0 commit comments

Comments
 (0)