From 4f47d279b536ad0d7603e80689e766870b0b3239 Mon Sep 17 00:00:00 2001 From: Juan C Galvis <8420868+juancgalvis@users.noreply.github.com> Date: Wed, 7 Feb 2024 15:52:38 -0500 Subject: [PATCH 1/2] fix vuln with force dependency resolution --- commons-jms-mq/commons-jms-mq.gradle | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/commons-jms-mq/commons-jms-mq.gradle b/commons-jms-mq/commons-jms-mq.gradle index 3932b81..080e254 100644 --- a/commons-jms-mq/commons-jms-mq.gradle +++ b/commons-jms-mq/commons-jms-mq.gradle @@ -5,6 +5,12 @@ dependencies { implementation 'org.springframework.boot:spring-boot-actuator' } +configurations.configureEach { + resolutionStrategy { + force 'org.json:json:20240205' // to avoid CVE-2023-5072 + } +} + ext { artifactId = 'commons-jms-mq' artifactDescription = 'Commons JMS MQ' From 746e07a3a20269b8ec5e59f0add6b165dac9e9e7 Mon Sep 17 00:00:00 2001 From: Juan C Galvis <8420868+juancgalvis@users.noreply.github.com> Date: Wed, 7 Feb 2024 15:53:00 -0500 Subject: [PATCH 2/2] fix vuln with force dependency resolution --- gradle.properties | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/gradle.properties b/gradle.properties index 52086ee..4d2e379 100644 --- a/gradle.properties +++ b/gradle.properties @@ -1,4 +1,4 @@ -version=2.0.0 +version=2.0.1 springBootVersion=3.2.1 gradleVersionsVersion=0.47.0 owaspDependencyCheckVersion=9.0.9