diff --git a/service/evaka-bom/build.gradle.kts b/service/evaka-bom/build.gradle.kts index 04bbd7bde89..c665c527f1c 100644 --- a/service/evaka-bom/build.gradle.kts +++ b/service/evaka-bom/build.gradle.kts @@ -10,7 +10,7 @@ dependencies { constraints { api("ch.qos.logback.access:tomcat:2.0.2") api( - "org.apache.tomcat:tomcat-catalina:10.1.26" + "org.apache.tomcat:tomcat-catalina:10.1.31" ) // ch.qos.logback.access:tomcat breaks on runtime without this api("com.auth0:java-jwt:4.4.0") api("com.github.kagkarlsson:db-scheduler:15.0.0") @@ -64,7 +64,7 @@ dependencies { api(enforcedPlatform("org.eclipse.jetty:jetty-bom:11.0.20")) api(platform("org.jdbi:jdbi3-bom:3.47.0")) api(platform(libs.kotlin.bom)) - api(platform("org.junit:junit-bom:5.11.0")) + api(platform("org.junit:junit-bom:5.11.3")) api(platform(libs.spring.boot.dependencies)) api(platform("org.springframework:spring-framework-bom:6.1.14")) // only needed for CVE fix api(platform("software.amazon.awssdk:bom:2.29.1")) diff --git a/service/gradle/libs.versions.toml b/service/gradle/libs.versions.toml index 03d8700bce1..4959b925986 100644 --- a/service/gradle/libs.versions.toml +++ b/service/gradle/libs.versions.toml @@ -15,7 +15,7 @@ ktlint = "1.4.0" ktlint-gradle = "12.1.0" mockito = "5.14.0" owasp = "11.1.0" -spring-boot = "3.3.2" +spring-boot = "3.3.5" versions = "0.51.0" [libraries] diff --git a/service/owasp-suppressions.xml b/service/owasp-suppressions.xml index 179df3a8099..a933da56275 100644 --- a/service/owasp-suppressions.xml +++ b/service/owasp-suppressions.xml @@ -7,18 +7,6 @@ SPDX-License-Identifier: LGPL-2.1-or-later --> - - - CVE-2023-38286 - - - - CVE-2023-4586 - - ^pkg:maven/org\.apache\.tomcat/tomcat-jaspic-api@10\.1\.26$ + ^pkg:maven/org\.apache\.tomcat/tomcat-jaspic-api@10\.1\.31$ cpe:/a:apache:tomcat:3.0 - ^pkg:maven/org\.apache\.tomcat/tomcat-jsp-api@10\.1\.26$ + ^pkg:maven/org\.apache\.tomcat/tomcat-jsp-api@10\.1\.31$ cpe:/a:apache:tomcat:3.1 - - - ^pkg:maven/org\.flywaydb/flyway\-database\-postgresql@.*$ - cpe:/a:postgresql:postgresql - - - - CVE-2024-1597 - - - - CVE-2024-9329 - - - - CVE-2024-38828 -