From ee53c30ee29a1ad7d272ba1d05db38e2f3c5925b Mon Sep 17 00:00:00 2001 From: YANGDB Date: Mon, 5 Feb 2024 15:58:11 -0800 Subject: [PATCH 1/4] fix cve issues related to logback Signed-off-by: YANGDB --- build.gradle | 2 ++ 1 file changed, 2 insertions(+) diff --git a/build.gradle b/build.gradle index 73a037fa1..c839f207a 100644 --- a/build.gradle +++ b/build.gradle @@ -188,6 +188,8 @@ allprojects { } dependencies { + implementation "ch.qos.logback:logback-classic:1.3.12" + implementation "ch.qos.logback:logback-core:1.3.0-alpha0" implementation "org.opensearch:opensearch:${opensearch_version}" implementation "org.jetbrains.kotlin:kotlin-stdlib:${kotlin_version}" implementation "org.jetbrains.kotlin:kotlin-stdlib-common:${kotlin_version}" From a94ed8f4a0c76f06e6da99773a3196e92e819722 Mon Sep 17 00:00:00 2001 From: YANGDB Date: Mon, 5 Feb 2024 16:07:16 -0800 Subject: [PATCH 2/4] fix cve issues related to logback Signed-off-by: YANGDB --- build.gradle | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/build.gradle b/build.gradle index c839f207a..c5bb75e2d 100644 --- a/build.gradle +++ b/build.gradle @@ -188,7 +188,6 @@ allprojects { } dependencies { - implementation "ch.qos.logback:logback-classic:1.3.12" implementation "ch.qos.logback:logback-core:1.3.0-alpha0" implementation "org.opensearch:opensearch:${opensearch_version}" implementation "org.jetbrains.kotlin:kotlin-stdlib:${kotlin_version}" @@ -214,7 +213,7 @@ dependencies { testImplementation "org.mockito:mockito-junit-jupiter:4.3.1" testImplementation "com.google.code.gson:gson:2.8.9" - ktlint "com.pinterest:ktlint:0.45.0" + ktlint "com.pinterest:ktlint:0.47.1" } javadoc.enabled = false // turn off javadoc as it barfs on Kotlin code From 55b65dc1988709e5ec2cfb794ace4ea6d36be2aa Mon Sep 17 00:00:00 2001 From: YANGDB Date: Mon, 5 Feb 2024 16:33:36 -0800 Subject: [PATCH 3/4] fix cve issues related to logback Signed-off-by: YANGDB --- build.gradle | 1 - 1 file changed, 1 deletion(-) diff --git a/build.gradle b/build.gradle index c5bb75e2d..21d64f9c5 100644 --- a/build.gradle +++ b/build.gradle @@ -188,7 +188,6 @@ allprojects { } dependencies { - implementation "ch.qos.logback:logback-core:1.3.0-alpha0" implementation "org.opensearch:opensearch:${opensearch_version}" implementation "org.jetbrains.kotlin:kotlin-stdlib:${kotlin_version}" implementation "org.jetbrains.kotlin:kotlin-stdlib-common:${kotlin_version}" From c6fc50ada4e9e38e924ea47540166d97c6c27827 Mon Sep 17 00:00:00 2001 From: YANGDB Date: Mon, 5 Feb 2024 16:45:50 -0800 Subject: [PATCH 4/4] fix cve issues related to logback Signed-off-by: YANGDB --- build.gradle | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/build.gradle b/build.gradle index 21d64f9c5..9ffb35c4f 100644 --- a/build.gradle +++ b/build.gradle @@ -153,7 +153,7 @@ configurations.all { force "org.jetbrains.kotlin:kotlin-stdlib-common:${kotlin_version}" force "com.fasterxml.jackson.dataformat:jackson-dataformat-cbor:${jackson_version}" force "org.mockito:mockito-core:4.6.1" - force "org.yaml:snakeyaml:2.0" + force "org.yaml:snakeyaml:2.1" } }