Skip to content

Commit cb3600a

Browse files
chore: upgrade grpc due to vuln (#48)
* upgrade grpc and auth0 libs * update * revert jwks change
1 parent df9fb71 commit cb3600a

File tree

7 files changed

+14
-6
lines changed

7 files changed

+14
-6
lines changed
+1-1
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
distributionBase=GRADLE_USER_HOME
22
distributionPath=wrapper/dists
3-
distributionUrl=https\://services.gradle.org/distributions/gradle-6.5-all.zip
3+
distributionUrl=https\://services.gradle.org/distributions/gradle-7.6-all.zip
44
zipStoreBase=GRADLE_USER_HOME
55
zipStorePath=wrapper/dists

grpc-client-rx-utils/build.gradle.kts

+1-1
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ plugins {
66
}
77

88
dependencies {
9-
api(platform("io.grpc:grpc-bom:1.56.0"))
9+
api(platform("io.grpc:grpc-bom:1.57.2"))
1010
api("io.reactivex.rxjava3:rxjava:3.1.4")
1111
api("io.grpc:grpc-stub")
1212
api(project(":grpc-context-utils"))

grpc-client-utils/build.gradle.kts

+1-1
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ plugins {
77

88
dependencies {
99

10-
api(platform("io.grpc:grpc-bom:1.56.0"))
10+
api(platform("io.grpc:grpc-bom:1.57.2"))
1111
api("io.grpc:grpc-context")
1212
api("io.grpc:grpc-api")
1313
api(platform("io.netty:netty-bom:4.1.94.Final")) {

grpc-context-utils/build.gradle.kts

+1-1
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ tasks.test {
1010
}
1111

1212
dependencies {
13-
api(platform("io.grpc:grpc-bom:1.56.0"))
13+
api(platform("io.grpc:grpc-bom:1.57.2"))
1414
implementation("io.grpc:grpc-core")
1515

1616
implementation("com.auth0:java-jwt:4.4.0")

grpc-server-rx-utils/build.gradle.kts

+1-1
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ plugins {
66
}
77

88
dependencies {
9-
api(platform("io.grpc:grpc-bom:1.56.0"))
9+
api(platform("io.grpc:grpc-bom:1.57.2"))
1010
api("io.reactivex.rxjava3:rxjava:3.1.4")
1111
api("io.grpc:grpc-stub")
1212

grpc-server-utils/build.gradle.kts

+1-1
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ tasks.test {
1010
}
1111

1212
dependencies {
13-
api(platform("io.grpc:grpc-bom:1.56.0"))
13+
api(platform("io.grpc:grpc-bom:1.57.2"))
1414
api("io.grpc:grpc-context")
1515
api("io.grpc:grpc-api")
1616

owasp-suppressions.xml

+8
Original file line numberDiff line numberDiff line change
@@ -7,4 +7,12 @@
77
<packageUrl regex="true">^pkg:maven/org\.hypertrace\..*@.*$</packageUrl>
88
<cpe>cpe:/a:grpc:grpc</cpe>
99
</suppress>
10+
<suppress until="2023-08-31Z">
11+
<notes><![CDATA[
12+
file name: jackson-databind-2.14.2.jar
13+
This is currently disputed.
14+
]]></notes>
15+
<packageUrl regex="true">^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$</packageUrl>
16+
<cve>CVE-2023-35116</cve>
17+
</suppress>
1018
</suppressions>

0 commit comments

Comments
 (0)