fix security issues due to transitive dependency icu4j #2
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
(Copy from linkedin#790)
These dependencies are brought in when using latest release of rest.li
--- org.antlr:antlr4:4.7.2
+--- org.antlr:antlr4-runtime:4.7.2
+--- org.antlr:antlr-runtime:3.5.2
+--- org.antlr:ST4:4.1
| --- org.antlr:antlr-runtime:3.5.2
+--- org.abego.treelayout:org.abego.treelayout.core:1.0.3
+--- org.glassfish:javax.json:1.0.4
--- com.ibm.icu:icu4j:61.1
OWASP scanner on a sample project shows these vulnerabilities
Upgrading to latest 4.10.1 we get these
--- org.antlr:antlr4:4.10.1
+--- org.antlr:antlr4-runtime:4.10.1
+--- org.antlr:antlr-runtime:3.5.3
+--- org.antlr:ST4:4.3.3
| --- org.antlr:antlr-runtime:3.5.2 -> 3.5.3
+--- org.abego.treelayout:org.abego.treelayout.core:1.0.3
+--- org.glassfish:javax.json:1.0.4
--- com.ibm.icu:icu4j:69.1
After update 0 CVEs
Ref
https://plugins.gradle.org/plugin/org.owasp.dependencycheck
https://jeremylong.github.io/DependencyCheck/dependency-check-gradle/index.html