From 642c7dc2d2330e7b4984ecfa350b3433c3f73b1a Mon Sep 17 00:00:00 2001 From: Gary O'Neall Date: Fri, 24 Oct 2025 11:43:15 -0700 Subject: [PATCH] Update library and plugin versions --- dependency-check-supress.xml | 136 ++++++++++++++++++----------------- pom.xml | 52 +++++++++----- 2 files changed, 108 insertions(+), 80 deletions(-) diff --git a/dependency-check-supress.xml b/dependency-check-supress.xml index 6984b4e..00a186a 100644 --- a/dependency-check-supress.xml +++ b/dependency-check-supress.xml @@ -1,67 +1,75 @@ - - - ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-core@.*$ - CVE-2023-5072 - - - - ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-core@.*$ - CVE-2023-5072 - - - - ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$ - CVE-2023-35116 - - - - ^pkg:maven/org\.glassfish/jakarta\.json@.*$ - CVE-2022-45688 - - - - ^pkg:maven/org\.glassfish/jakarta\.json@.*$ - CVE-2023-5072 - - - - ^pkg:maven/com\.github\.jsonld\-java/jsonld\-java@.*$ - CVE-2022-45688 - - - - ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-core@.*$ - CVE-2022-45688 - - - - ^pkg:maven/com\.github\.jsonld\-java/jsonld\-java@.*$ - CVE-2023-5072 - + + + ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-core@.*$ + CVE-2023-5072 + + + + ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-core@.*$ + CVE-2023-5072 + + + + ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$ + CVE-2023-35116 + + + + ^pkg:maven/org\.glassfish/jakarta\.json@.*$ + CVE-2022-45688 + + + + ^pkg:maven/org\.glassfish/jakarta\.json@.*$ + CVE-2023-5072 + + + + ^pkg:maven/com\.github\.jsonld\-java/jsonld\-java@.*$ + CVE-2022-45688 + + + + ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-core@.*$ + CVE-2022-45688 + + + + ^pkg:maven/com\.github\.jsonld\-java/jsonld\-java@.*$ + CVE-2023-5072 + + + + ^pkg:maven/com\.ibm\.icu/icu4j@.*$ + CVE-2025-5222 + \ No newline at end of file diff --git a/pom.xml b/pom.xml index 2de23db..923efcd 100644 --- a/pom.xml +++ b/pom.xml @@ -38,7 +38,7 @@ spdx licenseListPublisher 11 - 8.0.1 + 12.1.8 @@ -60,22 +60,22 @@ commons-cli commons-cli - 1.5.0 + 1.10.0 commons-codec commons-codec - 1.15 + 1.19.0 commons-io commons-io - 2.14.0 + 2.20.0 commons-validator commons-validator - 1.7 + 1.10.0 net.sf.opencsv @@ -90,17 +90,17 @@ org.spdx spdx-rdf-store - 2.0.0 + 2.0.1 org.spdx java-spdx-library - 2.0.0 + 2.0.1 org.spdx spdx-v3jsonld-store - 1.0.0 + 1.0.1 @@ -120,7 +120,7 @@ org.apache.maven.plugins maven-source-plugin - 3.2.1 + 3.3.1 attach-sources @@ -134,7 +134,7 @@ org.apache.maven.plugins maven-gpg-plugin - 1.6 + 3.2.8 sign-artifacts @@ -152,7 +152,7 @@ org.apache.maven.plugins maven-javadoc-plugin - 2.9.1 + 3.12.0 true 8 @@ -224,7 +224,7 @@ org.apache.maven.plugins maven-release-plugin - 3.0.1 + 3.1.1 v@{project.version} release @@ -234,12 +234,32 @@ org.sonatype.central central-publishing-maven-plugin - 0.7.0 + 0.9.0 true central + + org.apache.maven.plugins + maven-enforcer-plugin + 3.6.2 + + + enforce-maven + + enforce + + + + + 3.6.3 + + + + + + org.apache.maven.plugins maven-shade-plugin @@ -297,7 +317,7 @@ org.spdx spdx-maven-plugin - 1.0.0 + 1.0.3 build-spdx @@ -338,7 +358,7 @@ org.apache.maven.plugins maven-compiler-plugin - 3.11.0 + 3.14.1 1.8 1.8 @@ -351,7 +371,7 @@ org.apache.maven.plugins maven-resources-plugin - 2.6 + 3.3.1 ${project.build.sourceEncoding}