From 32fe8ee4de9b5325488147d89a257c42f78d457f Mon Sep 17 00:00:00 2001 From: snyk-bot Date: Mon, 28 Jul 2025 07:49:22 +0000 Subject: [PATCH] fix: pom.xml to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JAVA-ORGAPACHECOMMONS-10734078 --- pom.xml | 1622 +++++++++++++++++++++++++++---------------------------- 1 file changed, 811 insertions(+), 811 deletions(-) diff --git a/pom.xml b/pom.xml index e6527c0..bac0baf 100644 --- a/pom.xml +++ b/pom.xml @@ -1,814 +1,814 @@ - + - 4.0.0 - com.norconex.commons - norconex-commons-lang - 3.0.0-SNAPSHOT - jar - Norconex Commons Lang - - 2008 - - - 17 - ${java.version} - ${java.version} - ${java.version} - - UTF-8 - UTF-8 - norconex - https://sonarcloud.io - **com/fasterxml/jackson/dataformat/xml/ser/**/* - - 4.4 - 2.16.1 - 3.14.0 - 1.12.0 - 8.0.1.Final - 4.2 - 6.0.1 - 10k - 1.8 - 2.17.2 - 2.24.3 - 4.10.0 - 2.0.14 - 4.0.5 - - 11.0.0-M18 - 2.3 - 2.12.2 - 4.0.2 - 2.1.100 - - - 1.10.13 - 3.24.2 - 5.9.3 - 1.16.0 - - - 1.18.34 - - - - 2.24.1 - - - - - - - The Apache Software License, Version 2.0 - https://www.apache.org/licenses/LICENSE-2.0.txt - - - - - - sonatype-oss-snapshots - Sonatype OSS Snapshot Repository - https://oss.sonatype.org/content/repositories/snapshots - - false - - - true - - - - - - - - org.apache.commons - commons-lang3 - ${commons-lang3.version} - - - org.apache.commons - commons-collections4 - ${commons-collections4.version} - - - commons-io - commons-io - ${commons-io.version} - - - org.apache.commons - commons-text - ${commons-text.version} - - - org.apache.velocity - velocity-engine-core - ${velocity-engine.version} - - - org.slf4j - slf4j-api - ${slf4j.version} - - - org.imgscalr - imgscalr-lib - ${imgscalr-lib.version} - - - - - org.exist-db.thirdparty.xerces - xercesImpl - ${xerces.version} - xml-schema-1.1 - - - - xml-apis - xml-apis - - - - - - com.rackspace.eclipse.webtools.sourceediting - org.eclipse.wst.xml.xpath2.processor - ${xpath2.version} - - - - jakarta.xml.bind - jakarta.xml.bind-api - ${xml-bind-api.version} - - - - com.sun.xml.bind - jaxb-impl - ${sun-jaxb-impl.version} - runtime - - - - edu.princeton.cup - java-cup - ${java-cup.version} - runtime - - - - com.tdunning - json - ${json.version} - - - - - - - org.assertj - assertj-core - ${assertj.version} - test - - - org.junit.jupiter - junit-jupiter - ${junit-jupiter.version} - test - - - org.apache.logging.log4j - log4j-slf4j2-impl - ${log4j.version} - test - - - org.apache.ant - ant - ${ant.version} - test - - - org.slf4j - jcl-over-slf4j - ${slf4j.version} - test - - - - - com.fasterxml.jackson.core - jackson-annotations - ${jackson.version} - - - com.fasterxml.jackson.dataformat - jackson-dataformat-yaml - ${jackson.version} - - - com.fasterxml.jackson.datatype - jackson-datatype-jsr310 - ${jackson.version} - - - com.fasterxml.jackson.core - jackson-databind - ${jackson.version} - - - com.fasterxml.jackson.module - jackson-module-parameter-names - ${jackson.version} - - - com.fasterxml.jackson.datatype - jackson-datatype-jdk8 - ${jackson.version} - - - com.fasterxml.jackson.dataformat - jackson-dataformat-xml - ${jackson.version} - - - org.hibernate.validator - hibernate-validator - ${hibernate.version} - - - jakarta.el - jakarta.el-api - ${jakarta-el-api.version} - - - - org.apache.tomcat.embed - tomcat-embed-el - ${tomcat-embed-el.version} - - - - - - com.squareup.okhttp3 - okhttp - ${okhttp3.version} - test - - - com.squareup.okhttp3 - mockwebserver - ${okhttp3.version} - test - - - com.squareup.okhttp3 - okhttp-tls - ${okhttp3.version} - test - - - - - org.projectlombok - lombok - ${lombok.version} - provided - - - - - - - - - false - ${project.build.sourceDirectory} - - **/* - - - **/*.java - - - - false - src/main/resources - - **/* - - - - false - ${project.basedir} - ${project.build.directory}/site - - CHANGES.xml - - - - - - false - ${project.build.testSourceDirectory} - - **/* - - - **/*.java - - - - false - src/test/resources - - **/* - - - - - - org.apache.maven.wagon - wagon-ssh - 3.5.3 - - - - - - - net.revelc.code.formatter - formatter-maven-plugin - ${formatter-maven-plugin.version} - - - - format - - - - - ${java.version} - ${java.version} - ${java.version} - LF - UTF-8 - norconex-formatter.xml - - com/norconex/**/*.java - - - true - - - - - - - - org.jacoco - jacoco-maven-plugin - 0.8.10 - - - prepare-agent - - prepare-agent - - - - report - - report - - - - XML - - - - - - - - org.projectlombok - lombok-maven-plugin - 1.18.20.0 - - - org.projectlombok - lombok - ${lombok.version} - - - - - org.apache.commons - commons-lang3 - ${commons-lang3.version} - - - com.fasterxml.jackson.core - jackson-annotations - ${jackson.version} - - - - - - - delombok - generate-sources - - delombok - - - false - ${project.basedir}/src/main/java - - - - test-delombok - generate-test-sources - - testDelombok - - - false - ${project.basedir}/src/test/java - - - - - - - org.codehaus.mojo - license-maven-plugin - 2.0.0 - - - download-licenses - - download-licenses - - generate-resources - - - - - - - org.apache.maven.plugins - maven-assembly-plugin - - - make-resources-assembly - package - - single - - - - src/main/assembly/resources.xml - - true - - - - make-dist-assembly - package - - single - - - - src/main/assembly/dist.xml - - false - - - - - - - org.apache.maven.plugins - maven-compiler-plugin - 3.13.0 - - ${maven.compiler.source} - ${maven.compiler.target} - UTF-8 - - - org.projectlombok - lombok - ${lombok.version} - - - - - - - org.apache.maven.plugins - maven-remote-resources-plugin - 3.0.0 - - - - org.apache.maven.plugins - maven-javadoc-plugin - 3.10.0 - - ${project.build.directory} - ${project.build.directory}/generated-sources/delombok - - com/norconex/**/*.java - - - com/fasterxml/**/*.java - com/norconex/commons/lang/javadoc/**/*.java - - - -Xdoclint:all - -Xdoclint:-missing - - protected - false - false - - - - https://commons.apache.org/proper/commons-lang/javadocs/api-release - https://commons.apache.org/proper/commons-collections/javadocs/api-${commons-collections4.version} - https://commons.apache.org/proper/commons-io/javadocs/api-release - https://commons.apache.org/proper/commons-text/apidocs - https://commons.apache.org/proper/commons-cli/javadocs/api-release - https://commons.apache.org/proper/commons-logging/javadocs/api-release - https://velocity.apache.org/engine/${velocity-engine.version}/apidocs - https://www.slf4j.org/apidocs - - - - - - make-javadoc - prepare-package - - jar - - - - - - - org.apache.maven.plugins - maven-source-plugin - 3.3.1 - - - attach-sources - - jar-no-fork - - - - - - - org.apache.maven.plugins - maven-jar-plugin - 3.3.0 - - - - true - true - - - - THIRD-PARTY.txt - - - - - - test-jar - - - - - - - org.apache.maven.plugins - maven-surefire-plugin - 3.0.0 - - - - - org.apache.maven.plugins - maven-gpg-plugin - 3.0.1 - - - sign-artifacts - verify - - sign - - - - - --pinentry-mode - loopback - - - - - - - - org.sonatype.plugins - nexus-staging-maven-plugin - 1.6.13 - true - - ossrh - https://oss.sonatype.org/ - false - - - - - org.apache.maven.plugins - maven-site-plugin - 4.0.0-M16 - - - org.apache.maven.wagon - wagon-ssh - 3.5.2 - - - - - - - org.codehaus.mojo - versions-maven-plugin - 2.15.0 - - - compile - - display-dependency-updates - display-plugin-updates - display-property-updates - - - - - - - org.apache.maven.plugins - maven-enforcer-plugin - 3.5.0 - - - enforce-versions - - enforce - - - - - [3.8,) - - - [17,) - - - - - - - - - net.revelc.code.formatter - formatter-maven-plugin - - - - - - - - - ossrh - https://oss.sonatype.org/content/repositories/snapshots - - - ossrh - https://oss.sonatype.org/service/local/staging/deploy/maven2/ - - - - site-deployment - ${site.baseurl}/commons/lang/v3 - - - - Norconex Inc. - https://norconex.com - - https://opensource.norconex.com/commons/lang - - Norconex Commons Lang is a Java library containing utility classes that - complements the Java API and are not found in commonly available - libraries (such as the great Apache Commons Lang, which it relies on). - - - https://github.com/Norconex/commons-lang - scm:git:git@github.com:Norconex/commons-lang.git - scm:git:git@github.com:Norconex/commons-lang.git - - - GitHub - https://github.com/Norconex/commons-lang/issues - - - - - essiembre - Pascal Essiembre - pascal.essiembre@norconex.com - Norconex Inc. - https://norconex.com - - project leader - developer - - -4 - - - - - - + xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd"> + 4.0.0 + com.norconex.commons + norconex-commons-lang + 3.0.0-SNAPSHOT + jar + Norconex Commons Lang + + 2008 + + + 17 + ${java.version} + ${java.version} + ${java.version} + + UTF-8 + UTF-8 + norconex + https://sonarcloud.io + **com/fasterxml/jackson/dataformat/xml/ser/**/* + + 4.4 + 2.16.1 + 3.14.0 + 1.14.0 + 8.0.1.Final + 4.2 + 6.0.1 + 10k + 1.8 + 2.17.2 + 2.24.3 + 4.10.0 + 2.0.14 + 4.0.5 + + 11.0.0-M18 + 2.3 + 2.12.2 + 4.0.2 + 2.1.100 + + + 1.10.13 + 3.24.2 + 5.9.3 + 1.16.0 + + + 1.18.34 + + + + 2.24.1 + + + + + + + The Apache Software License, Version 2.0 + https://www.apache.org/licenses/LICENSE-2.0.txt + + + + + + sonatype-oss-snapshots + Sonatype OSS Snapshot Repository + https://oss.sonatype.org/content/repositories/snapshots + + false + + + true + + + + + + + + org.apache.commons + commons-lang3 + ${commons-lang3.version} + + + org.apache.commons + commons-collections4 + ${commons-collections4.version} + + + commons-io + commons-io + ${commons-io.version} + + + org.apache.commons + commons-text + ${commons-text.version} + + + org.apache.velocity + velocity-engine-core + ${velocity-engine.version} + + + org.slf4j + slf4j-api + ${slf4j.version} + + + org.imgscalr + imgscalr-lib + ${imgscalr-lib.version} + + + + + org.exist-db.thirdparty.xerces + xercesImpl + ${xerces.version} + xml-schema-1.1 + + + + xml-apis + xml-apis + + + + + + com.rackspace.eclipse.webtools.sourceediting + org.eclipse.wst.xml.xpath2.processor + ${xpath2.version} + + + + jakarta.xml.bind + jakarta.xml.bind-api + ${xml-bind-api.version} + + + + com.sun.xml.bind + jaxb-impl + ${sun-jaxb-impl.version} + runtime + + + + edu.princeton.cup + java-cup + ${java-cup.version} + runtime + + + + com.tdunning + json + ${json.version} + + + + + + + org.assertj + assertj-core + ${assertj.version} + test + + + org.junit.jupiter + junit-jupiter + ${junit-jupiter.version} + test + + + org.apache.logging.log4j + log4j-slf4j2-impl + ${log4j.version} + test + + + org.apache.ant + ant + ${ant.version} + test + + + org.slf4j + jcl-over-slf4j + ${slf4j.version} + test + + + + + com.fasterxml.jackson.core + jackson-annotations + ${jackson.version} + + + com.fasterxml.jackson.dataformat + jackson-dataformat-yaml + ${jackson.version} + + + com.fasterxml.jackson.datatype + jackson-datatype-jsr310 + ${jackson.version} + + + com.fasterxml.jackson.core + jackson-databind + ${jackson.version} + + + com.fasterxml.jackson.module + jackson-module-parameter-names + ${jackson.version} + + + com.fasterxml.jackson.datatype + jackson-datatype-jdk8 + ${jackson.version} + + + com.fasterxml.jackson.dataformat + jackson-dataformat-xml + ${jackson.version} + + + org.hibernate.validator + hibernate-validator + ${hibernate.version} + + + jakarta.el + jakarta.el-api + ${jakarta-el-api.version} + + + + org.apache.tomcat.embed + tomcat-embed-el + ${tomcat-embed-el.version} + + + + + + com.squareup.okhttp3 + okhttp + ${okhttp3.version} + test + + + com.squareup.okhttp3 + mockwebserver + ${okhttp3.version} + test + + + com.squareup.okhttp3 + okhttp-tls + ${okhttp3.version} + test + + + + + org.projectlombok + lombok + ${lombok.version} + provided + + + + + + + + + false + ${project.build.sourceDirectory} + + **/* + + + **/*.java + + + + false + src/main/resources + + **/* + + + + false + ${project.basedir} + ${project.build.directory}/site + + CHANGES.xml + + + + + + false + ${project.build.testSourceDirectory} + + **/* + + + **/*.java + + + + false + src/test/resources + + **/* + + + + + + org.apache.maven.wagon + wagon-ssh + 3.5.3 + + + + + + + net.revelc.code.formatter + formatter-maven-plugin + ${formatter-maven-plugin.version} + + + + format + + + + + ${java.version} + ${java.version} + ${java.version} + LF + UTF-8 + norconex-formatter.xml + + com/norconex/**/*.java + + + true + + + + + + + + org.jacoco + jacoco-maven-plugin + 0.8.10 + + + prepare-agent + + prepare-agent + + + + report + + report + + + + XML + + + + + + + + org.projectlombok + lombok-maven-plugin + 1.18.20.0 + + + org.projectlombok + lombok + ${lombok.version} + + + + + org.apache.commons + commons-lang3 + ${commons-lang3.version} + + + com.fasterxml.jackson.core + jackson-annotations + ${jackson.version} + + + + + + + delombok + generate-sources + + delombok + + + false + ${project.basedir}/src/main/java + + + + test-delombok + generate-test-sources + + testDelombok + + + false + ${project.basedir}/src/test/java + + + + + + + org.codehaus.mojo + license-maven-plugin + 2.0.0 + + + download-licenses + + download-licenses + + generate-resources + + + + + + + org.apache.maven.plugins + maven-assembly-plugin + + + make-resources-assembly + package + + single + + + + src/main/assembly/resources.xml + + true + + + + make-dist-assembly + package + + single + + + + src/main/assembly/dist.xml + + false + + + + + + + org.apache.maven.plugins + maven-compiler-plugin + 3.13.0 + + ${maven.compiler.source} + ${maven.compiler.target} + UTF-8 + + + org.projectlombok + lombok + ${lombok.version} + + + + + + + org.apache.maven.plugins + maven-remote-resources-plugin + 3.0.0 + + + + org.apache.maven.plugins + maven-javadoc-plugin + 3.10.0 + + ${project.build.directory} + ${project.build.directory}/generated-sources/delombok + + com/norconex/**/*.java + + + com/fasterxml/**/*.java + com/norconex/commons/lang/javadoc/**/*.java + + + -Xdoclint:all + -Xdoclint:-missing + + protected + false + false + + + + https://commons.apache.org/proper/commons-lang/javadocs/api-release + https://commons.apache.org/proper/commons-collections/javadocs/api-${commons-collections4.version} + https://commons.apache.org/proper/commons-io/javadocs/api-release + https://commons.apache.org/proper/commons-text/apidocs + https://commons.apache.org/proper/commons-cli/javadocs/api-release + https://commons.apache.org/proper/commons-logging/javadocs/api-release + https://velocity.apache.org/engine/${velocity-engine.version}/apidocs + https://www.slf4j.org/apidocs + + + + + + make-javadoc + prepare-package + + jar + + + + + + + org.apache.maven.plugins + maven-source-plugin + 3.3.1 + + + attach-sources + + jar-no-fork + + + + + + + org.apache.maven.plugins + maven-jar-plugin + 3.3.0 + + + + true + true + + + + THIRD-PARTY.txt + + + + + + test-jar + + + + + + + org.apache.maven.plugins + maven-surefire-plugin + 3.0.0 + + + + + org.apache.maven.plugins + maven-gpg-plugin + 3.0.1 + + + sign-artifacts + verify + + sign + + + + + --pinentry-mode + loopback + + + + + + + + org.sonatype.plugins + nexus-staging-maven-plugin + 1.6.13 + true + + ossrh + https://oss.sonatype.org/ + false + + + + + org.apache.maven.plugins + maven-site-plugin + 4.0.0-M16 + + + org.apache.maven.wagon + wagon-ssh + 3.5.2 + + + + + + + org.codehaus.mojo + versions-maven-plugin + 2.15.0 + + + compile + + display-dependency-updates + display-plugin-updates + display-property-updates + + + + + + + org.apache.maven.plugins + maven-enforcer-plugin + 3.5.0 + + + enforce-versions + + enforce + + + + + [3.8,) + + + [17,) + + + + + + + + + net.revelc.code.formatter + formatter-maven-plugin + + + + + + + + + ossrh + https://oss.sonatype.org/content/repositories/snapshots + + + ossrh + https://oss.sonatype.org/service/local/staging/deploy/maven2/ + + + + site-deployment + ${site.baseurl}/commons/lang/v3 + + + + Norconex Inc. + https://norconex.com + + https://opensource.norconex.com/commons/lang + + Norconex Commons Lang is a Java library containing utility classes that + complements the Java API and are not found in commonly available + libraries (such as the great Apache Commons Lang, which it relies on). + + + https://github.com/Norconex/commons-lang + scm:git:git@github.com:Norconex/commons-lang.git + scm:git:git@github.com:Norconex/commons-lang.git + + + GitHub + https://github.com/Norconex/commons-lang/issues + + + + + essiembre + Pascal Essiembre + pascal.essiembre@norconex.com + Norconex Inc. + https://norconex.com + + project leader + developer + + -4 + + + + + +