Skip to content

Commit f1ec7b3

Browse files
committed
Update dependencies to address CVEs
1 parent 153e3c3 commit f1ec7b3

File tree

1 file changed

+8
-6
lines changed

1 file changed

+8
-6
lines changed

project.clj

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,11 @@
22
:min-lein-version "2.0.0"
33
:dependencies [[org.clojure/clojure "1.11.1"]
44
[org.clojure/core.memoize "1.0.253"]
5-
;; manage jetty dependency directly to make it easier to address CVEs
6-
;; addresses CVE-2021-34429
7-
[org.eclipse.jetty/jetty-server "9.4.44.v20210927"]
5+
;; manage jetty dependencies directly to make it easier to address CVEs
6+
[org.eclipse.jetty/jetty-client "9.4.49.v20220914"]
7+
[org.eclipse.jetty/jetty-server "9.4.49.v20220914"]
8+
;; manage jackson-databind directly to make it easiser to address CVEs
9+
[com.fasterxml.jackson.core/jackson-databind "2.14.0-rc1"]
810
[raven-clj "1.6.0"
911
:exclusions [cheshire]]
1012
[org.apache.maven/maven-model "3.8.4"]
@@ -18,8 +20,8 @@
1820
;; newer version brought in by com.cognitect.aws/api
1921
org.clojure/tools.reader
2022
org.yaml/snakeyaml]]
21-
;; addresses CVE-2017-18640
22-
[org.yaml/snakeyaml "1.30"]
23+
;; addresses CVEs
24+
[org.yaml/snakeyaml "1.33"]
2325
[org.apache.commons/commons-email "1.5"]
2426
[net.cgrand/regex "1.0.1"
2527
:exclusions [org.clojure/clojure]]
@@ -63,7 +65,7 @@
6365
[org.apache.lucene/lucene-queryparser "8.11.1"]
6466
[org.clojure/tools.nrepl "0.2.11"]
6567
[yesql "0.5.3"]
66-
[org.postgresql/postgresql "42.3.3"]
68+
[org.postgresql/postgresql "42.4.1"]
6769
[duct/hikaricp-component "0.1.2"
6870
:exclusions [com.stuartsierra/component
6971
org.slf4j/slf4j-api

0 commit comments

Comments
 (0)