Skip to content

Commit 231ef3d

Browse files
committed
Resolve more vulns in transitive dependencies
1 parent 5fe2e34 commit 231ef3d

1 file changed

Lines changed: 14 additions & 0 deletions

File tree

build.gradle

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -87,10 +87,24 @@ dependencies {
8787
implementation('commons-io:commons-io:2.19.0') {
8888
because 'spotify docker-client uses an outdated version'
8989
}
90+
implementation('org.apache.commons:commons-compress:1.27.1') {
91+
because 'spotify docker-client uses an outdated version'
92+
}
93+
implementation('org.apache.httpcomponents:httpclient:4.5.14') {
94+
because 'spotify docker-client uses an outdated version'
95+
}
9096
implementation('com.github.jnr:jnr-unixsocket:0.38.23') {
9197
because 'spotify docker-client uses an outdated version'
9298
}
9399
}
100+
modules {
101+
module('org.bouncycastle:bcpkix-jdk15on') {
102+
replacedBy('org.bouncycastle:bcpkix-jdk18on', "Everything can go via the JDK 1.8+ BouncyCastle version")
103+
}
104+
}
105+
implementation('org.bouncycastle:bcpkix-jdk18on:1.81') {
106+
because 'spotify docker-client uses an outdated version'
107+
}
94108
implementation(platform('com.fasterxml.jackson:jackson-bom:2.19.2')) // because 'spotify docker-client uses an outdated version'
95109

96110
testImplementation project.deps.gocdPluginApi

0 commit comments

Comments
 (0)