From 4f2ef4371ffad15f2dea9a83675d1800aeb3c4a8 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Thu, 27 Nov 2025 20:53:04 +0000 Subject: [PATCH 1/4] Initial plan From ffa886e001ed37388d10d4e3064e06c20f1b0e39 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Thu, 27 Nov 2025 21:03:44 +0000 Subject: [PATCH 2/4] Update all security dependencies across 22 PRs Co-authored-by: danregima <10253941+danregima@users.noreply.github.com> --- aperture-client/pom.xml | 2 +- aperture-server-core/pom.xml | 4 ++-- aperture-server/pom.xml | 6 +++--- bitcoin/pom.xml | 2 +- influent-app/pom.xml | 4 ++-- influent-selenium-test/pom.xml | 6 +++--- influent-server/pom.xml | 16 ++++++++-------- kiva/pom.xml | 2 +- opencog-integration/pom.xml | 2 +- pom.xml | 14 +++++++------- spotless-maven-plugin/pom.xml | 6 +++--- walker/pom.xml | 4 ++-- 12 files changed, 34 insertions(+), 34 deletions(-) diff --git a/aperture-client/pom.xml b/aperture-client/pom.xml index d3cddbab..7d7ea055 100644 --- a/aperture-client/pom.xml +++ b/aperture-client/pom.xml @@ -411,7 +411,7 @@ org.eclipse.jetty jetty-server - 12.1.3 + 12.1.4 diff --git a/aperture-server-core/pom.xml b/aperture-server-core/pom.xml index 458fe48a..a8981f0b 100644 --- a/aperture-server-core/pom.xml +++ b/aperture-server-core/pom.xml @@ -48,7 +48,7 @@ com.google.inject.extensions guice-servlet - 4.2.3 + 7.0.0 jar compile @@ -90,7 +90,7 @@ org.restlet.jee org.restlet.ext.servlet - 2.4.3 + 2.4.4 org.restlet.jee diff --git a/aperture-server/pom.xml b/aperture-server/pom.xml index 6a3f2fd7..0c035827 100644 --- a/aperture-server/pom.xml +++ b/aperture-server/pom.xml @@ -108,19 +108,19 @@ org.apache.shiro shiro-core - 1.13.0 + 2.0.6 compile org.apache.shiro shiro-web - 1.13.0 + 2.0.6 compile org.apache.shiro shiro-guice - 1.13.0 + 2.0.6 compile diff --git a/bitcoin/pom.xml b/bitcoin/pom.xml index 31dbf646..ae3e5638 100644 --- a/bitcoin/pom.xml +++ b/bitcoin/pom.xml @@ -316,7 +316,7 @@ org.eclipse.jetty jetty-server - 12.1.3 + 12.1.4 diff --git a/influent-app/pom.xml b/influent-app/pom.xml index 5ae97ada..fa7bb1e8 100644 --- a/influent-app/pom.xml +++ b/influent-app/pom.xml @@ -45,7 +45,7 @@ com.mysql mysql-connector-j - 8.4.0 + 9.5.0 @@ -322,7 +322,7 @@ org.eclipse.jetty jetty-server - 12.1.3 + 12.1.4 diff --git a/influent-selenium-test/pom.xml b/influent-selenium-test/pom.xml index 31176fdd..1d5b186d 100644 --- a/influent-selenium-test/pom.xml +++ b/influent-selenium-test/pom.xml @@ -24,7 +24,7 @@ org.seleniumhq.selenium selenium-java - 4.37.0 + 4.38.0 @@ -36,13 +36,13 @@ org.seleniumhq.selenium selenium-chrome-driver - 4.37.0 + 4.38.0 org.seleniumhq.selenium selenium-ie-driver - 4.34.0 + 4.38.0 diff --git a/influent-server/pom.xml b/influent-server/pom.xml index eca8f849..99f4a8ee 100644 --- a/influent-server/pom.xml +++ b/influent-server/pom.xml @@ -104,27 +104,27 @@ org.apache.shiro shiro-core - 1.13.0 + 2.0.6 compile org.eclipse.persistence org.eclipse.persistence.moxy - 4.0.7 + 4.0.8 org.apache.shiro shiro-web - 1.13.0 + 2.0.6 compile org.apache.shiro shiro-guice - 1.13.0 + 2.0.6 compile @@ -137,7 +137,7 @@ commons-io commons-io - 2.20.0 + 2.21.0 @@ -162,7 +162,7 @@ com.google.inject.extensions guice-servlet - 4.2.3 + 7.0.0 @@ -182,7 +182,7 @@ org.apache.commons commons-lang3 - 3.19.0 + 3.20.0 @@ -281,7 +281,7 @@ org.apache.maven.plugins maven-surefire-plugin - 3.5.3 + 3.5.4 false diff --git a/kiva/pom.xml b/kiva/pom.xml index d18a0391..bdac5976 100644 --- a/kiva/pom.xml +++ b/kiva/pom.xml @@ -365,7 +365,7 @@ org.eclipse.jetty jetty-server - 12.1.3 + 12.1.4 diff --git a/opencog-integration/pom.xml b/opencog-integration/pom.xml index 7fa042ee..311dcc27 100644 --- a/opencog-integration/pom.xml +++ b/opencog-integration/pom.xml @@ -16,7 +16,7 @@ Integration module providing OpenCog AtomSpace and reasoning capabilities for Influent data flow analytics - 2.7.3 + 2.7.4 0.10.9.9 1.5.0 diff --git a/pom.xml b/pom.xml index bc1dc0f9..fe53cec8 100644 --- a/pom.xml +++ b/pom.xml @@ -165,7 +165,7 @@ org.owasp dependency-check-maven - 12.1.8 + 12.1.9 7 dependency-check-suppressions.xml @@ -199,7 +199,7 @@ org.codehaus.mojo versions-maven-plugin - 2.19.1 + 2.20.1 false @@ -228,7 +228,7 @@ org.apache.maven.plugins maven-surefire-plugin - 3.5.3 + 3.5.4 org.apache.maven.plugins @@ -238,7 +238,7 @@ org.apache.maven.plugins maven-jar-plugin - 3.4.2 + 3.5.0 false @@ -272,7 +272,7 @@ org.apache.maven.plugins maven-javadoc-plugin - 3.11.2 + 3.12.0 none false @@ -405,7 +405,7 @@ com.google.inject.extensions guice-multibindings - 4.2.3 + 7.0.0 @@ -466,7 +466,7 @@ com.fasterxml.jackson.core jackson-core - 2.19.2 + 2.20.1 diff --git a/spotless-maven-plugin/pom.xml b/spotless-maven-plugin/pom.xml index 0e59e932..561f8f9b 100644 --- a/spotless-maven-plugin/pom.xml +++ b/spotless-maven-plugin/pom.xml @@ -49,14 +49,14 @@ com.diffplug.spotless spotless-lib - 4.0.0 + 4.1.0 com.diffplug.spotless spotless-lib-extra - 4.0.0 + 4.1.0 @@ -130,7 +130,7 @@ org.codehaus.mojo versions-maven-plugin - 2.19.1 + 2.20.1 false diff --git a/walker/pom.xml b/walker/pom.xml index 42a9f6b8..5e5a3b37 100644 --- a/walker/pom.xml +++ b/walker/pom.xml @@ -51,7 +51,7 @@ com.mysql mysql-connector-j - 8.4.0 + 9.5.0 @@ -328,7 +328,7 @@ org.eclipse.jetty jetty-server - 12.1.3 + 12.1.4 From 63fa1e8925a3a6c8659569f00a22736e3c4730b1 Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Thu, 27 Nov 2025 21:11:19 +0000 Subject: [PATCH 3/4] Fix guice-multibindings version - not available in 7.0.0 Co-authored-by: danregima <10253941+danregima@users.noreply.github.com> --- aperture-server-core/pom.xml | 2 +- influent-selenium-test/dependency-reduced-pom.xml | 4 ++-- pom.xml | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/aperture-server-core/pom.xml b/aperture-server-core/pom.xml index a8981f0b..a5fc2402 100644 --- a/aperture-server-core/pom.xml +++ b/aperture-server-core/pom.xml @@ -90,7 +90,7 @@ org.restlet.jee org.restlet.ext.servlet - 2.4.4 + 2.4.3 org.restlet.jee diff --git a/influent-selenium-test/dependency-reduced-pom.xml b/influent-selenium-test/dependency-reduced-pom.xml index 5235c324..edd9b31f 100644 --- a/influent-selenium-test/dependency-reduced-pom.xml +++ b/influent-selenium-test/dependency-reduced-pom.xml @@ -14,11 +14,11 @@ com.diffplug.spotless spotless-maven-plugin - 2.46.1 + 3.0.0 maven-shade-plugin - 3.6.0 + 3.6.1 package diff --git a/pom.xml b/pom.xml index fe53cec8..7f3b7fed 100644 --- a/pom.xml +++ b/pom.xml @@ -405,7 +405,7 @@ com.google.inject.extensions guice-multibindings - 7.0.0 + 4.2.3 From 90d1949feee9f4953d368fd66cd34ab8b413410e Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Thu, 27 Nov 2025 21:16:01 +0000 Subject: [PATCH 4/4] Revert guice-servlet and Apache Shiro to maintain servlet API compatibility Co-authored-by: danregima <10253941+danregima@users.noreply.github.com> --- aperture-server-core/pom.xml | 2 +- aperture-server/pom.xml | 6 +++--- influent-server/pom.xml | 8 ++++---- pom.xml | 2 +- 4 files changed, 9 insertions(+), 9 deletions(-) diff --git a/aperture-server-core/pom.xml b/aperture-server-core/pom.xml index a5fc2402..458fe48a 100644 --- a/aperture-server-core/pom.xml +++ b/aperture-server-core/pom.xml @@ -48,7 +48,7 @@ com.google.inject.extensions guice-servlet - 7.0.0 + 4.2.3 jar compile diff --git a/aperture-server/pom.xml b/aperture-server/pom.xml index 0c035827..6a3f2fd7 100644 --- a/aperture-server/pom.xml +++ b/aperture-server/pom.xml @@ -108,19 +108,19 @@ org.apache.shiro shiro-core - 2.0.6 + 1.13.0 compile org.apache.shiro shiro-web - 2.0.6 + 1.13.0 compile org.apache.shiro shiro-guice - 2.0.6 + 1.13.0 compile diff --git a/influent-server/pom.xml b/influent-server/pom.xml index 99f4a8ee..25027c79 100644 --- a/influent-server/pom.xml +++ b/influent-server/pom.xml @@ -104,7 +104,7 @@ org.apache.shiro shiro-core - 2.0.6 + 1.13.0 compile @@ -117,14 +117,14 @@ org.apache.shiro shiro-web - 2.0.6 + 1.13.0 compile org.apache.shiro shiro-guice - 2.0.6 + 1.13.0 compile @@ -162,7 +162,7 @@ com.google.inject.extensions guice-servlet - 7.0.0 + 4.2.3 diff --git a/pom.xml b/pom.xml index 7f3b7fed..05cd2fb5 100644 --- a/pom.xml +++ b/pom.xml @@ -411,7 +411,7 @@ com.google.inject.extensions guice-servlet - 7.0.0 + 4.2.3