Details
-
Bug
-
Status: Closed (View Workflow)
-
P2
-
Resolution: Done
-
None
-
-
Sif
-
TBD
Description
Update log4j from both 1.2.17 and 2.13.3 to 2.17.1 fixing
- https://nvd.nist.gov/vuln/detail/CVE-2022-23305
- https://nvd.nist.gov/vuln/detail/CVE-2022-23302
- https://nvd.nist.gov/vuln/detail/CVE-2021-45105
- https://nvd.nist.gov/vuln/detail/CVE-2021-45046
- https://nvd.nist.gov/vuln/detail/CVE-2021-44832
- https://nvd.nist.gov/vuln/detail/CVE-2021-4104
- https://nvd.nist.gov/vuln/detail/CVE-2019-17571
Update Vert.x from 4.0.0 to 4.2.4, this updates Netty and jackson-databind.
Indirectly update Netty from 4.1.42 to 4.1.73 fixing:
Indirectly update jackson-databind from 2.10.2 to 2.13.1 fixing
Update okapi-common from 3.1.3 to 4.12.0.
Remove raml-module-builder (RMB) reducing
the fat jar size from 49 MB to 9 MB and
the Docker image size from 225 MB to 184MB.
Update junit from 4.12 to 4.13.2 fixing
Update rest-assured from 2.8.0 to 4.5.0.