diff --git a/.circleci/config.yml b/.circleci/config.yml index b94096bf0..81046d534 100644 --- a/.circleci/config.yml +++ b/.circleci/config.yml @@ -186,8 +186,9 @@ jobs: destination: distributions - run: name: Dependency vulnerability scan + no_output_timeout: 40m command: | - ./gradlew --no-daemon -Dorg.gradle.parallel=false dependencyCheckAggregate + ./gradlew --no-daemon -Dorg.gradle.parallel=false dependencyCheckAggregate -DnvdApiDelay=6000 - run: name: Test no_output_timeout: 20m diff --git a/build.gradle b/build.gradle index 2737a095b..c36984c40 100644 --- a/build.gradle +++ b/build.gradle @@ -25,7 +25,7 @@ buildscript { } dependencies { classpath 'tech.pegasys.internal.license.reporter:license-reporter:1.0.1' - classpath 'org.owasp:dependency-check-gradle:8.4.2' + classpath 'org.owasp:dependency-check-gradle:9.0.2' } } diff --git a/gradle/owasp-suppression.xml b/gradle/owasp-suppression.xml index 0ef47a82e..8ef642f96 100644 --- a/gradle/owasp-suppression.xml +++ b/gradle/owasp-suppression.xml @@ -20,13 +20,6 @@ ^pkg:maven/com\.azure/azure\-identity@1\.10\.[2-9]$ CVE-2023-36415 - - - ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$ - CVE-2023-35116 - ^pkg:maven/com\.squareup\.okhttp3/.*$ CVE-2023-3782 + + + ^pkg:maven/com\.azure/azure*@*.*$ + CVE-2023-36052 + + + + ^pkg:maven/io\.grpc/grpc\-.*$ + CVE-2023-44487 + diff --git a/gradle/versions.gradle b/gradle/versions.gradle index 46c56daab..5f30d5da2 100644 --- a/gradle/versions.gradle +++ b/gradle/versions.gradle @@ -13,8 +13,8 @@ dependencyManagement { dependencies { - dependency 'com.fasterxml.jackson.core:jackson-databind:2.15.2' - dependency 'com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.15.2' + dependency 'com.fasterxml.jackson.core:jackson-databind:2.16.0' + dependency 'com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.16.0' dependencySet(group: 'com.google.errorprone', version: '2.21.1') { entry 'error_prone_annotation' @@ -85,8 +85,8 @@ dependencyManagement { entry 'mockito-junit-jupiter' } - dependency 'org.hyperledger.besu:plugin-api:23.10.1' - dependency 'org.hyperledger.besu.internal:metrics-core:23.10.1' + dependency 'org.hyperledger.besu:plugin-api:23.10.2' + dependency 'org.hyperledger.besu.internal:metrics-core:23.10.2' dependency 'org.xipki.iaik:sunpkcs11-wrapper:1.4.10' @@ -175,7 +175,7 @@ dependencyManagement { dependency 'com.squareup.okio:okio:3.4.0' // addressing CVE-2023-44487 - dependencySet(group: 'io.netty', version: '4.1.100.Final') { + dependencySet(group: 'io.netty', version: '4.1.101.Final') { entry 'netty-all' entry 'netty-codec-http2' entry 'netty-handler' @@ -217,7 +217,7 @@ dependencyManagement { // besu 23.10.1 uses grpc 1.53.0 so vulnerable to // CVE-2023-32731, CVE-2023-33953, CVE-2023-44487, CVE-2023-4785 - dependencySet(group: 'io.grpc', version: '1.59.0') { + dependencySet(group: 'io.grpc', version: '1.59.1') { entry 'grpc-all' entry 'grpc-core' entry 'grpc-netty'