From cd6dc7f73f6361c558f206ca3b3b1d752eaf1762 Mon Sep 17 00:00:00 2001 From: kagw95 Date: Wed, 11 Feb 2026 20:39:26 +0400 Subject: [PATCH 1/3] fix(security): Bump dependencies versions to fix vulnerabilities found by Security-Scanner. --- mockingbird-aggregator/pom.xml | 4 ++ mockingbird-integration-atp2/pom.xml | 4 ++ mockingbird-template-velocity/pom.xml | 4 ++ parent/parent-dependencies/pom.xml | 75 +++++++++++++++++++++++---- parent/parent-java/pom.xml | 6 --- 5 files changed, 78 insertions(+), 15 deletions(-) diff --git a/mockingbird-aggregator/pom.xml b/mockingbird-aggregator/pom.xml index 5d3179e..3cdb34b 100644 --- a/mockingbird-aggregator/pom.xml +++ b/mockingbird-aggregator/pom.xml @@ -449,6 +449,10 @@ org.apache.kafka kafka-clients + + at.yawk.lz4 + lz4-java + org.springframework.kafka spring-kafka diff --git a/mockingbird-integration-atp2/pom.xml b/mockingbird-integration-atp2/pom.xml index 5610179..69406de 100644 --- a/mockingbird-integration-atp2/pom.xml +++ b/mockingbird-integration-atp2/pom.xml @@ -73,6 +73,10 @@ + + at.yawk.lz4 + lz4-java + org.springframework.cloud spring-cloud-sleuth-zipkin diff --git a/mockingbird-template-velocity/pom.xml b/mockingbird-template-velocity/pom.xml index 065838d..d6e7c47 100644 --- a/mockingbird-template-velocity/pom.xml +++ b/mockingbird-template-velocity/pom.xml @@ -58,6 +58,10 @@ com.nimbusds nimbus-jose-jwt + + commons-collections + commons-collections + com.ibm.icu icu4j diff --git a/parent/parent-dependencies/pom.xml b/parent/parent-dependencies/pom.xml index 40ee7d4..cebe582 100644 --- a/parent/parent-dependencies/pom.xml +++ b/parent/parent-dependencies/pom.xml @@ -21,6 +21,7 @@ 4.4.114 2.2.7 1.2.75 + 0.0.47 0.0.13 0.2.46 0.0.24 @@ -34,7 +35,7 @@ 4.9.3 3.4.3.Final 3.8.14.Final - 2.2.38.Final + 2.2.39.Final 2.2.11 5.0.3 11.10 @@ -45,6 +46,7 @@ 2.8.0 3.2.1 9.4.57.v20241219 + 2.15.0 @@ -583,6 +585,10 @@ commons-lang commons-lang + + commons-collections + commons-collections + @@ -681,27 +687,27 @@ com.fasterxml.jackson.core jackson-databind - 2.12.7.1 + ${jackson.version} com.fasterxml.jackson.core jackson-core - 2.12.7 + ${jackson.version} com.fasterxml.jackson.core jackson-annotations - 2.12.7 + ${jackson.version} com.fasterxml.jackson.datatype jackson-datatype-joda - 2.12.7 + ${jackson.version} com.fasterxml.jackson.module jackson-module-jaxb-annotations - 2.12.7 + ${jackson.version} commons-codec @@ -840,7 +846,7 @@ io.springfox springfox-swagger-ui - 2.9.2 + 2.10.0 com.nimbusds @@ -1027,7 +1033,17 @@ io.undertow undertow-core - ${io.undertow.undertow-core.version} + ${io.undertow.version} + + + io.undertow + undertow-servlet + ${io.undertow.version} + + + io.undertow + undertow-websockets-jsr + ${io.undertow.version} com.sun.xml.bind @@ -1132,7 +1148,18 @@ org.apache.kafka kafka-clients - 3.7.2 + 3.9.1 + + + org.lz4 + lz4-java + + + + + at.yawk.lz4 + lz4-java + 1.10.1 org.postgresql @@ -1145,6 +1172,36 @@ + + org.qubership.atp.common + qubership-atp-common-probes + ${atp.common.version} + + + org.qubership.atp.common + qubership-atp-common-monitoring-undertow + ${atp.common.version} + + + org.qubership.atp.common + qubership-atp-common-utils + ${atp.common.version} + + + org.qubership.atp.common + qubership-atp-common-logging + ${atp.common.version} + + + org.assertj + assertj-core + 3.27.7 + + + org.springframework.kafka + spring-kafka + 2.9.11 + diff --git a/parent/parent-java/pom.xml b/parent/parent-java/pom.xml index e3a3058..9287226 100644 --- a/parent/parent-java/pom.xml +++ b/parent/parent-java/pom.xml @@ -12,7 +12,6 @@ UTF-8 UTF-8 - 0.0.43 @@ -24,11 +23,6 @@ pom import - - org.qubership.atp.common - qubership-atp-common-probes - ${atp.common.version} - From c0dab43950a087052ab36b00dd8f757f1e41bed6 Mon Sep 17 00:00:00 2001 From: kagw95 Date: Thu, 12 Feb 2026 10:54:40 +0400 Subject: [PATCH 2/3] fix(security): Bump dependencies versions: activemq to 5.16.8, atp-integration to 0.2.42, io.netty to 4.1.125.Final, reactor-netty to 1.0.39, guava to 32.0.1-jre, commons-compress to 1.21, nimbus-jose-jwt to 9.37.2, commons-lang3 to 3.18.0. --- mockingbird-core/pom.xml | 10 ++-- parent/parent-dependencies/pom.xml | 75 +++++++++++++++++++++--------- 2 files changed, 56 insertions(+), 29 deletions(-) diff --git a/mockingbird-core/pom.xml b/mockingbird-core/pom.xml index ef6badb..6a0bb83 100644 --- a/mockingbird-core/pom.xml +++ b/mockingbird-core/pom.xml @@ -237,12 +237,10 @@ org.qubership.atp atp-itf-core - + + + org.qubership.atp + atp-integration-spring-boot-starter org.qubership.automation diff --git a/parent/parent-dependencies/pom.xml b/parent/parent-dependencies/pom.xml index cebe582..b7a8f0b 100644 --- a/parent/parent-dependencies/pom.xml +++ b/parent/parent-dependencies/pom.xml @@ -15,13 +15,14 @@ 2021.0.8 22.0.1 2.20.4 - 5.12.2 + 5.16.8 1.8.10 4.4.114 2.2.7 1.2.75 0.0.47 + 0.2.42 0.0.13 0.2.46 0.0.24 @@ -31,7 +32,7 @@ 5.2 1.2.17 1.69 - 4.1.44.Final + 4.1.125.Final 4.9.3 3.4.3.Final 3.8.14.Final @@ -91,8 +92,21 @@ org.apache.tomcat.embed tomcat-embed-websocket + + org.apache.tomcat.embed + tomcat-embed-el + + + org.qubership.atp + atp-integration-spring-boot-starter + + + org.qubership.atp + atp-integration-spring-boot-starter + ${atp.integration.version} + @@ -232,10 +246,30 @@ + + io.projectreactor.netty + reactor-netty + 1.0.39 + + + io.netty + netty-all + ${io.netty.version} + io.netty netty-handler - 4.1.118.Final + ${io.netty.version} + + + io.netty + netty-codec-http + ${io.netty.version} + + + io.netty + netty-codec-http2 + ${io.netty.version} com.datastax.cassandra @@ -371,16 +405,6 @@ lombok 1.14.8 - - io.netty - netty-all - ${io.netty.netty.version} - - - io.projectreactor.netty - reactor-netty - 0.9.8.RELEASE - com.squareup.okhttp3 okhttp @@ -1202,6 +1226,11 @@ spring-kafka 2.9.11 + + org.apache.commons + commons-lang3 + 3.18.0 + From fea207e8fed97900c8d8006b813610a41b7071b9 Mon Sep 17 00:00:00 2001 From: kagw95 Date: Thu, 12 Feb 2026 10:56:34 +0400 Subject: [PATCH 3/3] fix: Dependencies management is improved for SMPP and SQL modules. --- .../mockingbird-transport-smpp/pom.xml | 6 +++--- .../mockingbird-transport-sql/pom.xml | 6 +++--- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/mockingbird-transports-camel/mockingbird-transport-smpp/pom.xml b/mockingbird-transports-camel/mockingbird-transport-smpp/pom.xml index b2f552f..4967f11 100644 --- a/mockingbird-transports-camel/mockingbird-transport-smpp/pom.xml +++ b/mockingbird-transports-camel/mockingbird-transport-smpp/pom.xml @@ -35,8 +35,8 @@ ${project.build.directory}/lib/${project.build.finalName} - - + true + runtime diff --git a/mockingbird-transports-camel/mockingbird-transport-sql/pom.xml b/mockingbird-transports-camel/mockingbird-transport-sql/pom.xml index 71c22ea..a04855f 100644 --- a/mockingbird-transports-camel/mockingbird-transport-sql/pom.xml +++ b/mockingbird-transports-camel/mockingbird-transport-sql/pom.xml @@ -30,8 +30,8 @@ ${project.build.directory}/lib/${project.build.finalName} - - + true + runtime