Skip to content

Commit 8b4e3c8

Browse files
tuncaytunc-zfflorianrusch-zf
authored andcommitted
build(deps): Move Gradle dependencies constrains into root build.gradle.kts (#273)
Co-authored-by: Florian Rusch (ZF Friedrichshafen AG) <florian.rusch.external@zf.com>
1 parent 8c6e842 commit 8b4e3c8

File tree

4 files changed

+11
-17
lines changed

4 files changed

+11
-17
lines changed

build.gradle.kts

+11
Original file line numberDiff line numberDiff line change
@@ -159,3 +159,14 @@ subprojects {
159159
}
160160
}
161161
}
162+
163+
dependencies {
164+
constraints {
165+
implementation("org.yaml:snakeyaml:2.0") {
166+
because("version 1.33 has vulnerabilities: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1471.")
167+
}
168+
implementation("net.minidev:json-smart:2.4.10") {
169+
because("version 2.4.8 has vulnerabilities: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1370.")
170+
}
171+
}
172+
}

edc-controlplane/edc-controlplane-postgresql/build.gradle.kts

-5
Original file line numberDiff line numberDiff line change
@@ -11,11 +11,6 @@ dependencies {
1111
runtimeOnly(project(":edc-controlplane:edc-controlplane-base"))
1212
runtimeOnly(project(":edc-extensions:postgresql-migration"))
1313
runtimeOnly(edc.azure.vault)
14-
constraints {
15-
implementation("net.minidev:json-smart:2.4.10") {
16-
because("version 2.4.8 has vulnerabilities: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1370.")
17-
}
18-
}
1914
runtimeOnly(edc.bundles.sqlstores)
2015
runtimeOnly(edc.transaction.local)
2116
runtimeOnly(edc.sql.pool)

edc-dataplane/edc-dataplane-azure-vault/build.gradle.kts

-5
Original file line numberDiff line numberDiff line change
@@ -8,11 +8,6 @@ plugins {
88
dependencies {
99
implementation(project(":edc-dataplane:edc-dataplane-base"))
1010
implementation(edc.azure.vault)
11-
constraints {
12-
implementation("net.minidev:json-smart:2.4.10") {
13-
because("version 2.4.8 has vulnerabilities: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1370.")
14-
}
15-
}
1611
implementation(edc.azure.identity)
1712
implementation("com.azure:azure-security-keyvault-secrets:4.6.0")
1813
}

edc-extensions/control-plane-adapter/build.gradle.kts

-7
Original file line numberDiff line numberDiff line change
@@ -8,14 +8,7 @@ plugins {
88
dependencies {
99
implementation(edc.spi.core)
1010
implementation(edc.spi.policy)
11-
1211
implementation(edc.api.management)
13-
constraints {
14-
implementation("org.yaml:snakeyaml:2.0") {
15-
because("version 1.33 has vulnerabilities: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1471.")
16-
}
17-
}
18-
1912
implementation(edc.spi.catalog)
2013
implementation(edc.spi.transactionspi)
2114
implementation(edc.spi.transaction.datasource)

0 commit comments

Comments
 (0)