From 27e444501e73c96c14a2af111f01d6b4ffccc583 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Pere=20Fern=C3=A1ndez?= Date: Mon, 30 Oct 2023 11:23:40 +0100 Subject: [PATCH] NO_ISSUE: Overriding commons-compress version to fix CVE-2023-42503 present in 1.22 --- kogito-build/kogito-dependencies-bom/pom.xml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/kogito-build/kogito-dependencies-bom/pom.xml b/kogito-build/kogito-dependencies-bom/pom.xml index 704ab81459c..21a11e42a55 100644 --- a/kogito-build/kogito-dependencies-bom/pom.xml +++ b/kogito-build/kogito-dependencies-bom/pom.xml @@ -126,6 +126,7 @@ 1.0-1 4.1.1 32.0.1-jre + 1.24.0 @@ -136,6 +137,13 @@ guava ${version.com.google.guava} + + + org.apache.commons + commons-compress + ${version.apache.commons.commons-compress} + + org.slf4j slf4j-api