Commit 9ccdd68
Security patch (#1333)
* Bump ch.qos.logback:logback-classic in /core-services/egov-user (#1310)
Bumps [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) from 1.2.0 to 1.2.13.
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.2.0...v_1.2.13)
---
updated-dependencies:
- dependency-name: ch.qos.logback:logback-classic
dependency-version: 1.2.13
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Bump org.postgresql:postgresql in /core-services/egov-location (#1311)
Bumps [org.postgresql:postgresql](https://github.com/pgjdbc/pgjdbc) from 42.7.7 to 42.7.11.
- [Release notes](https://github.com/pgjdbc/pgjdbc/releases)
- [Changelog](https://github.com/pgjdbc/pgjdbc/blob/master/CHANGELOG.md)
- [Commits](pgjdbc/pgjdbc@REL42.7.7...REL42.7.11)
---
updated-dependencies:
- dependency-name: org.postgresql:postgresql
dependency-version: 42.7.11
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Fix: pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
* Dependabot/maven/tutorials/backend developer guide/btr service/net.minidev json smart 2.5.2 (#1314)
* Bump net.minidev:json-smart
Bumps [net.minidev:json-smart](https://github.com/netplex/json-smart-v2) from 2.5.0 to 2.5.2.
- [Release notes](https://github.com/netplex/json-smart-v2/releases)
- [Commits](netplex/json-smart-v2@2.5.0...2.5.2)
---
updated-dependencies:
- dependency-name: net.minidev:json-smart
dependency-version: 2.5.2
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* updated json-smart version
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Dependabot/maven/core services/egov malware detection/commons io commons io 2.14.0 (#1316)
* Bump commons-io:commons-io in /core-services/egov-malware-detection
Bumps commons-io:commons-io from 2.11.0 to 2.14.0.
---
updated-dependencies:
- dependency-name: commons-io:commons-io
dependency-version: 2.14.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* updated common.io
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Dependabot/maven/core services/egov user/org.jsoup jsoup 1.15.3 (#1317)
* Bump org.jsoup:jsoup from 1.10.2 to 1.15.3 in /core-services/egov-user
Bumps [org.jsoup:jsoup](https://github.com/jhy/jsoup) from 1.10.2 to 1.15.3.
- [Release notes](https://github.com/jhy/jsoup/releases)
- [Changelog](https://github.com/jhy/jsoup/blob/jsoup-1.15.3/CHANGES)
- [Commits](jhy/jsoup@jsoup-1.10.2...jsoup-1.15.3)
---
updated-dependencies:
- dependency-name: org.jsoup:jsoup
dependency-version: 1.15.3
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
* Update jsoup dependency version to 1.15.3
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Bump io.minio:minio from 7.1.4 to 8.6.0 in /core-services/egov-filestore (#1318)
Bumps [io.minio:minio](https://github.com/minio/minio-java) from 7.1.4 to 8.6.0.
- [Release notes](https://github.com/minio/minio-java/releases)
- [Commits](minio/minio-java@7.1.4...8.6.0)
---
updated-dependencies:
- dependency-name: io.minio:minio
dependency-version: 8.6.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Bump io.minio:minio in /core-services/egov-malware-detection (#1319)
Bumps [io.minio:minio](https://github.com/minio/minio-java) from 8.5.7 to 8.6.0.
- [Release notes](https://github.com/minio/minio-java/releases)
- [Commits](minio/minio-java@8.5.7...8.6.0)
---
updated-dependencies:
- dependency-name: io.minio:minio
dependency-version: 8.6.0
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Bump com.amazonaws:aws-java-sdk-s3 in /core-services/egov-filestore (#1321)
Bumps [com.amazonaws:aws-java-sdk-s3](https://github.com/aws/aws-sdk-java) from 1.11.289 to 1.12.261.
- [Changelog](https://github.com/aws/aws-sdk-java/blob/master/CHANGELOG.md)
- [Commits](aws/aws-sdk-java@1.11.289...1.12.261)
---
updated-dependencies:
- dependency-name: com.amazonaws:aws-java-sdk-s3
dependency-version: 1.12.261
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Kafka client will transitively pull the dependency
* Update tracer dependency version to 2.9.2-SNAPSHOT
* Filestore changes due to minio major version change
* Feat: Updated tracer version to 2.9.2
* Fix: Removed hardcoded postgresql version
* Patches for vulnerabilites
* Changes to dependencies in utilites
* Change branch for push trigger to 'security-patch'
* Clean up permissions in scorecard.yml (#1330)
Removed commented-out permissions for private repositories.
* Add workflow_dispatch trigger to scorecard workflow
Allows manual triggering from GitHub Actions UI and fixes the job condition
to not skip runs triggered via workflow_dispatch on non-default branches.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Fix scorecard publish_results to allow runs on non-default branches
publish_results: true causes scorecard-action to abort on any branch
other than master. Making it conditional lets manual/PR runs complete.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Update scorecard.yml
* Update scorecard.yml
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: talele08 <talele08@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: talele08 <talele.aniket@gmail.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent b4f1845 commit 9ccdd68
34 files changed
Lines changed: 58 additions & 20 deletions
File tree
- .github/workflows
- accelerators/gateway-kubernetes-discovery
- core-services
- audit-service
- boundary-service
- egov-accesscontrol
- egov-enc-service
- egov-filestore
- egov-idgen
- egov-indexer
- egov-localization
- egov-location
- egov-malware-detection
- egov-mdms-service
- egov-notification-mail
- egov-notification-sms
- egov-otp
- egov-persister
- egov-pg-service
- egov-url-shortening
- egov-user
- egov-workflow-v2
- gateway
- internal-gateway-scg
- internal-gateway
- libraries
- enc-client
- mdms-client
- services-common
- tracer
- mdms-v2
- service-request
- user-otp
- zuul
- utilities
- boundary-migration
- mdms-migration-toolkit
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | | - | |
| 15 | + | |
| 16 | + | |
16 | 17 | | |
17 | 18 | | |
18 | 19 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | | - | |
8 | | - | |
| 7 | + | |
| 8 | + | |
9 | 9 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
| 19 | + | |
19 | 20 | | |
20 | 21 | | |
21 | 22 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
| 12 | + | |
| 13 | + | |
12 | 14 | | |
13 | 15 | | |
14 | 16 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
| 28 | + | |
28 | 29 | | |
29 | 30 | | |
30 | 31 | | |
| |||
83 | 84 | | |
84 | 85 | | |
85 | 86 | | |
86 | | - | |
| 87 | + | |
87 | 88 | | |
88 | 89 | | |
89 | 90 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
| 21 | + | |
21 | 22 | | |
22 | 23 | | |
23 | 24 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
| 25 | + | |
25 | 26 | | |
26 | 27 | | |
27 | 28 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| 23 | + | |
23 | 24 | | |
24 | 25 | | |
25 | 26 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
| 25 | + | |
25 | 26 | | |
26 | 27 | | |
27 | 28 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
| 22 | + | |
22 | 23 | | |
23 | 24 | | |
24 | 25 | | |
| |||
0 commit comments