@@ -204,6 +204,7 @@ Copyright (c) 2012 Jeremy Long. All Rights Reserved.
204204 <dependency >
205205 <groupId >io.github.jeremylong</groupId >
206206 <artifactId >jcs3-slf4j</artifactId >
207+ <scope >runtime</scope >
207208 </dependency >
208209 <dependency >
209210 <groupId >com.github.package-url</groupId >
@@ -340,14 +341,57 @@ Copyright (c) 2012 Jeremy Long. All Rights Reserved.
340341 <groupId >commons-validator</groupId >
341342 <artifactId >commons-validator</artifactId >
342343 </dependency >
343- <dependency ><!-- upgrade transitive dependency of commons-validator due to reported vulns-->
344- <groupId >commons-beanutils</groupId >
345- <artifactId >commons-beanutils</artifactId >
346- </dependency >
347344 <dependency >
348345 <groupId >org.eclipse.packager</groupId >
349346 <artifactId >packager-rpm</artifactId >
350347 </dependency >
348+ <dependency >
349+ <groupId >org.apache.httpcomponents.core5</groupId >
350+ <artifactId >httpcore5</artifactId >
351+ </dependency >
352+ <dependency >
353+ <groupId >org.apache.httpcomponents.client5</groupId >
354+ <artifactId >httpclient5</artifactId >
355+ </dependency >
356+ <dependency >
357+ <groupId >com.fasterxml.jackson.core</groupId >
358+ <artifactId >jackson-core</artifactId >
359+ </dependency >
360+ <dependency >
361+ <groupId >com.fasterxml.jackson.core</groupId >
362+ <artifactId >jackson-annotations</artifactId >
363+ </dependency >
364+ <dependency >
365+ <groupId >org.sonatype.goodies</groupId >
366+ <artifactId >package-url-java</artifactId >
367+ <version >1.1.1</version >
368+ </dependency >
369+ <dependency >
370+ <groupId >joda-time</groupId >
371+ <artifactId >joda-time</artifactId >
372+ <version >2.10.4</version >
373+ </dependency >
374+ <dependency >
375+ <groupId >org.sonatype.ossindex</groupId >
376+ <artifactId >ossindex-service-api</artifactId >
377+ <version >1.8.2</version >
378+ </dependency >
379+ <dependency >
380+ <groupId >com.esotericsoftware</groupId >
381+ <artifactId >minlog</artifactId >
382+ <version >1.3.1</version >
383+ </dependency >
384+ <dependency >
385+ <groupId >com.vaadin.external.google</groupId >
386+ <artifactId >android-json</artifactId >
387+ <version >0.0.20131108.vaadin1</version >
388+ </dependency >
389+ <dependency >
390+ <groupId >xml-apis</groupId >
391+ <artifactId >xml-apis</artifactId >
392+ <version >1.3.03</version >
393+ <scope >test</scope >
394+ </dependency >
351395 </dependencies >
352396 <profiles >
353397 <profile >
@@ -457,6 +501,48 @@ Copyright (c) 2012 Jeremy Long. All Rights Reserved.
457501 <activation >
458502 <activeByDefault >true</activeByDefault >
459503 </activation >
504+ <build >
505+ <pluginManagement >
506+ <plugins >
507+ <plugin >
508+ <groupId >org.apache.maven.plugins</groupId >
509+ <artifactId >maven-dependency-plugin</artifactId >
510+ <version >${maven-dependency-plugin.version} </version >
511+ <configuration >
512+ <usedDependencies combine.children=" append" >
513+ <!-- logback is our logging implementation during test and is test-scoped due to a lack of a
514+ test-runtime scope - it should be considered 'used' in the context of dependency:analyze-report -->
515+ <usedDependency >ch.qos.logback:logback-classic</usedDependency >
516+ <!-- dependencies to be copied for use in unit/integration testcases are, due to
517+ lack of a test-runtime scope, configured as test-scoped / optional and should be
518+ considered used for dependency:analyze-report -->
519+ <usedDependency >org.springframework:spring-webmvc</usedDependency >
520+ <usedDependency >org.mortbay.jetty:jetty</usedDependency >
521+ <usedDependency >net.sf.ehcache:ehcache-core</usedDependency >
522+ <usedDependency >com.google.inject:guice</usedDependency >
523+ <usedDependency >org.apache.struts:struts2-core</usedDependency >
524+ <usedDependency >xalan:xalan</usedDependency >
525+ <usedDependency >com.hazelcast:hazelcast</usedDependency >
526+ <usedDependency >commons-fileupload:commons-fileupload</usedDependency >
527+ <usedDependency >org.jslipc:jslipc</usedDependency >
528+ <usedDependency >com.thoughtworks.xstream:xstream</usedDependency >
529+ <usedDependency >org.dojotoolkit:dojo-war</usedDependency >
530+ <usedDependency >org.apache.openjpa:openjpa</usedDependency >
531+ <usedDependency >uk.ltd.getahead:dwr</usedDependency >
532+ <usedDependency >org.glassfish.main.admingui:war</usedDependency >
533+ <usedDependency >org.springframework.retry:spring-retry</usedDependency >
534+ <usedDependency >io.github.faob-dev:aar</usedDependency >
535+ <usedDependency >org.apache.maven.scm:maven-scm-provider-cvsexe</usedDependency >
536+ <usedDependency >org.apache.axis2:axis2-spring</usedDependency >
537+ <usedDependency >org.apache.geronimo.daytrader:daytrader-ear</usedDependency >
538+ <usedDependency >org.springframework.security:spring-security-web</usedDependency >
539+ <usedDependency >org.apache.axis2:axis2-adb</usedDependency >
540+ </usedDependencies >
541+ </configuration >
542+ </plugin >
543+ </plugins >
544+ </pluginManagement >
545+ </build >
460546 <dependencies >
461547 <!-- The following dependencies are only used during testing
462548 and must not be converted to a properties based version number -->
0 commit comments