Skip to content

Commit 398dbfa

Browse files
committed
fix vulnerabilities and upgrade backend dependency packages
1 parent e784ec3 commit 398dbfa

1 file changed

Lines changed: 11 additions & 3 deletions

File tree

build.gradle

Lines changed: 11 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -225,17 +225,25 @@ project(':dgrv4_Gateway_serv'){
225225

226226
implementation ('org.owasp.esapi:esapi:2.6.0.0'){
227227
exclude group:'commons-beanutils', module:'commons-beanutils'
228+
exclude group:'commons-fileupload', module:'commons-fileupload'
228229
}
229230

230-
// 修正上方排除的 commons-beanutils:commons-beanutils
231-
implementation 'commons-beanutils:commons-beanutils:1.11.0'
231+
// Correct the above exclusions, group:'commons-beanutils', module:'commons-beanutils'
232+
implementation 'commons-beanutils:commons-beanutils:1.11.0'
233+
// Correct the above exclusions, group:'commons-fileupload', module:'commons-fileupload'
234+
implementation 'commons-fileupload:commons-fileupload:1.6.0'
232235

233236
// gRPC Proxy
234237
implementation 'net.devh:grpc-server-spring-boot-starter:2.15.0.RELEASE'
235238
implementation 'io.grpc:grpc-netty-shaded:1.61.0'
236-
implementation 'io.grpc:grpc-protobuf:1.61.0'
239+
implementation ('io.grpc:grpc-protobuf:1.61.0'){
240+
exclude group:'com.google.protobuf', module:'protobuf-java'
241+
}
237242
implementation 'io.grpc:grpc-stub:1.61.0'
238243
implementation 'org.yaml:snakeyaml:2.2'
244+
245+
// Correct the above exclusions, group:'com.google.protobuf', module:'protobuf-java'
246+
implementation 'com.google.protobuf:protobuf-java:3.25.5'
239247

240248
// 添加對 Netty 的非遮蔽(non-shaded)依賴,以便 TLS 相關功能
241249
implementation 'io.grpc:grpc-netty:1.61.0'

0 commit comments

Comments
 (0)