From 95e0448bb5a9e22fbfe5679939b79c438cb2e72b Mon Sep 17 00:00:00 2001 From: Ben Companjen Date: Thu, 5 Dec 2024 17:57:29 +0100 Subject: [PATCH 1/6] Update Log4J to latest 2.x (cherry picked from commit 563b3849a46b152b0299c9f4a73699ae8f9030c2) --- pom.xml | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/pom.xml b/pom.xml index 676cbdf2..3e4fabce 100644 --- a/pom.xml +++ b/pom.xml @@ -12,6 +12,7 @@ 2.2.15 7.0 9.4.29.v20200521 + 2.24.2 @@ -144,17 +145,17 @@ org.apache.logging.log4j log4j-api - 2.17.1 + ${log4j.version} org.apache.logging.log4j log4j-core - 2.17.1 + ${log4j.version} org.apache.logging.log4j log4j-slf4j-impl - 2.16.0 + ${log4j.version} org.apache.solr From eed79d74854130c268abec8e775c74ad2f078bae Mon Sep 17 00:00:00 2001 From: Ben Companjen Date: Thu, 5 Dec 2024 18:42:25 +0100 Subject: [PATCH 2/6] Update various dependencies, add exclusions Commons logging was found in multiple (transitive) dependencies. (cherry picked from commit 49c31b95034bf8f127320f0af8bc133eb5b0b407) --- pom.xml | 55 ++++++++++++++++++++++++++++++++++++++++++++++++------- 1 file changed, 48 insertions(+), 7 deletions(-) diff --git a/pom.xml b/pom.xml index 3e4fabce..29ea8449 100644 --- a/pom.xml +++ b/pom.xml @@ -69,12 +69,17 @@ commons-codec commons-codec - 1.15 + 1.17.1 + + + commons-fileupload + commons-fileupload + 1.5 com.github.jsonld-java jsonld-java - 0.13.4 + 0.13.6 org.apache.httpcomponents @@ -94,7 +99,7 @@ jaxen jaxen - 1.2.0 + 2.0.0 org.jdom @@ -104,12 +109,12 @@ com.fasterxml.jackson.core jackson-core - 2.13.0 + 2.18.2 com.fasterxml.jackson.core jackson-databind - 2.13.2.1 + 2.18.2 org.openrdf.sesame @@ -124,7 +129,7 @@ org.apache.httpcomponents httpclient - 4.5.13 + 4.5.14 commons-logging @@ -167,11 +172,30 @@ org.elasticsearch.client elasticsearch-rest-high-level-client 7.13.4 + + + commons-logging + commons-logging + + com.amazonaws aws-java-sdk-core - 1.12.129 + 1.12.779 + + + commons-logging + commons-logging + + + + + + org.mockito + mockito-core + 5.14.2 + test junit @@ -179,6 +203,23 @@ 4.13.2 test + + + com.github.scribejava + scribejava-apis + 8.3.3 + + + org.springframework.security + spring-security-core + 6.4.1 + + + org.springframework + spring-jcl + + + simpleAnnotationStore From 39f4386f75ca0c24c61eabf5adb4a79ed425fb70 Mon Sep 17 00:00:00 2001 From: Ben Companjen Date: Mon, 9 Dec 2024 14:12:31 +0100 Subject: [PATCH 3/6] Revert Spring Security dependency to latest 5.x.y (cherry picked from commit 8c4eaca1e7a7b182d64069709c6990ecece8d168) --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 29ea8449..ad8472b3 100644 --- a/pom.xml +++ b/pom.xml @@ -212,7 +212,7 @@ org.springframework.security spring-security-core - 6.4.1 + 5.8.16 org.springframework From cb1f0297f769034b89d0ee39c3118169d82a9142 Mon Sep 17 00:00:00 2001 From: Ben Companjen Date: Thu, 5 Dec 2024 17:51:21 +0100 Subject: [PATCH 4/6] Update Jetty to latest v9, reuse version property (cherry picked from commit fbfb73dc53492c37b176b55a84efca7cc5128d2f) --- pom.xml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pom.xml b/pom.xml index ad8472b3..04e0175b 100644 --- a/pom.xml +++ b/pom.xml @@ -11,7 +11,7 @@ 2.2.15 7.0 - 9.4.29.v20200521 + 9.4.56.v20240826 2.24.2 @@ -243,7 +243,7 @@ org.eclipse.jetty jetty-maven-plugin - 9.4.30.v20200611 + ${jetty.version} 8888 @@ -261,7 +261,7 @@ org.eclipse.jetty apache-jstl - 9.4.29.v20200521 + ${jetty.version} org.apache.taglibs From 6ad07a49e03071c087725295896cf1363ecc59f4 Mon Sep 17 00:00:00 2001 From: Ben Companjen Date: Tue, 14 Jan 2025 12:31:31 +0100 Subject: [PATCH 5/6] Remove dependencies not in use --- pom.xml | 23 ----------------------- 1 file changed, 23 deletions(-) diff --git a/pom.xml b/pom.xml index 04e0175b..89fa6b6f 100644 --- a/pom.xml +++ b/pom.xml @@ -191,35 +191,12 @@ - - org.mockito - mockito-core - 5.14.2 - test - junit junit 4.13.2 test - - - com.github.scribejava - scribejava-apis - 8.3.3 - - - org.springframework.security - spring-security-core - 5.8.16 - - - org.springframework - spring-jcl - - - simpleAnnotationStore From 4ef663a1d5acd92eeb573a09fac01f386a182bef Mon Sep 17 00:00:00 2001 From: Ben Companjen Date: Tue, 14 Jan 2025 12:32:58 +0100 Subject: [PATCH 6/6] Remove commons-upload Maven dependency --- pom.xml | 5 ----- 1 file changed, 5 deletions(-) diff --git a/pom.xml b/pom.xml index 89fa6b6f..3d14ec85 100644 --- a/pom.xml +++ b/pom.xml @@ -71,11 +71,6 @@ commons-codec 1.17.1 - - commons-fileupload - commons-fileupload - 1.5 - com.github.jsonld-java jsonld-java