From 76e8909b4291ceb9fa1174f47ea3f21837caa80b Mon Sep 17 00:00:00 2001 From: David Whitlock Date: Thu, 1 Jan 2026 12:30:27 -0800 Subject: [PATCH 1/3] Update some libraries to remove CVEs. --- examples/pom.xml | 4 ++-- grader/pom.xml | 21 ++++++++++++++++++--- pom.xml | 8 ++++---- web/pom.xml | 6 +++--- 4 files changed, 27 insertions(+), 12 deletions(-) diff --git a/examples/pom.xml b/examples/pom.xml index 0de7c4b55..aaa03b532 100644 --- a/examples/pom.xml +++ b/examples/pom.xml @@ -29,12 +29,12 @@ jakarta.xml.bind jakarta.xml.bind-api - 4.0.2 + 4.0.4 com.sun.xml.bind jaxb-impl - 4.0.5 + 4.0.6 runtime diff --git a/grader/pom.xml b/grader/pom.xml index f3b42add6..1eae514b1 100644 --- a/grader/pom.xml +++ b/grader/pom.xml @@ -10,6 +10,21 @@ ${grader.version} jar https://www.cs.pdx.edu/~whitlock + + + + + commons-beanutils + commons-beanutils + 1.11.0 + + + org.apache.commons + commons-lang3 + 3.18.0 + + + com.sun.mail @@ -24,12 +39,12 @@ com.opencsv opencsv - 5.9 + 5.10 ch.qos.logback logback-classic - 1.5.19 + 1.5.21 com.google.inject @@ -39,7 +54,7 @@ com.icegreen greenmail - 2.0.1 + 2.1.2 test diff --git a/pom.xml b/pom.xml index edf37f061..aa22459cc 100644 --- a/pom.xml +++ b/pom.xml @@ -59,19 +59,19 @@ 33.5.0-jre 7.0.0 - 2.2.224 + 2.4.240 6.1.0 UTF-8 UTF-8 - 7.18.0 + 7.20.0 2.0.4 3.5.3 5.12.2 3.0 - 5.20.0 + 5.21.0 3.5.4 3.4.2 3.6.1 @@ -84,7 +84,7 @@ 3.9.0 3.5.4 3.6.0 - 12.1.2 + 12.3.1 3.4.0 3.12.0 3.28.0 diff --git a/web/pom.xml b/web/pom.xml index 1675b212f..b6c8715ba 100644 --- a/web/pom.xml +++ b/web/pom.xml @@ -12,7 +12,7 @@ 2.0.4-SNAPSHOT http://www.cs.pdx.edu/~whitlock - 6.2.11.Final + 6.2.12.Final 8080 @@ -112,7 +112,7 @@ commons-io commons-io - 2.18.0 + 2.21.0 io.github.davidwhitlock.joy @@ -127,7 +127,7 @@ jakarta.xml.bind jakarta.xml.bind-api - 4.0.2 + 4.0.4 org.jboss.resteasy From b234e9be9190560ed1eb49e6b039b56ca75a4b87 Mon Sep 17 00:00:00 2001 From: David Whitlock Date: Thu, 1 Jan 2026 12:43:15 -0800 Subject: [PATCH 2/3] Use the old version of greenmail. --- grader/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/grader/pom.xml b/grader/pom.xml index 1eae514b1..f2078a803 100644 --- a/grader/pom.xml +++ b/grader/pom.xml @@ -54,7 +54,7 @@ com.icegreen greenmail - 2.1.2 + 2.0.1 test From f9f2d9c911f64d3228fdc00f4fe3a2438fc5628d Mon Sep 17 00:00:00 2001 From: David Whitlock Date: Thu, 1 Jan 2026 12:47:53 -0800 Subject: [PATCH 3/3] A couple more dependency updates. --- grader/pom.xml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/grader/pom.xml b/grader/pom.xml index f2078a803..12420c0c8 100644 --- a/grader/pom.xml +++ b/grader/pom.xml @@ -39,12 +39,12 @@ com.opencsv opencsv - 5.10 + 5.12.0 ch.qos.logback logback-classic - 1.5.21 + 1.5.23 com.google.inject