Skip to content

Commit 54d8350

Browse files
authored
Merge pull request #15 from openapi-tools/feature/vulnerability-fix
Updating to avoid dependencies with vulnerabilities
2 parents 072b8e2 + f76bb6e commit 54d8350

2 files changed

Lines changed: 20 additions & 3 deletions

File tree

README.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,8 @@ The plugin is considered production ready. The version 2.x.x of the plugin is su
1111
[![Maven Central](https://maven-badges.herokuapp.com/maven-central/io.openapitools.swagger/swagger-maven-plugin/badge.svg)](https://maven-badges.herokuapp.com/maven-central/io.openapitools.swagger/swagger-maven-plugin/)
1212
[![Javadoc](https://javadoc.io/badge/io.openapitools.swagger/swagger-maven-plugin/badge.svg)](https://www.javadoc.io/doc/io.openapitools.swagger/swagger-maven-plugin)
1313
[![Build status](https://travis-ci.org/openapi-tools/swagger-maven-plugin.svg?branch=master)](https://travis-ci.org/openapi-tools/swagger-maven-plugin)
14+
[![Known Vulnerabilities](https://snyk.io/test/github/openapi-tools/swagger-maven-plugin/badge.svg)](https://snyk.io/test/github/openapi-tools/swagger-maven-plugin)
15+
1416

1517
# Usage
1618

pom.xml

Lines changed: 18 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -50,13 +50,15 @@
5050
<properties>
5151
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
5252
<project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding>
53-
54-
<io.swagger.core.v3.version>2.0.5</io.swagger.core.v3.version>
53+
54+
<com.fasterxml.jackson.core.version>2.9.8</com.fasterxml.jackson.core.version>
55+
<com.google.guava.version>27.0.1-jre</com.google.guava.version>
56+
<io.swagger.core.v3.version>2.0.6</io.swagger.core.v3.version>
5557
<junit.version>4.12</junit.version>
5658
<org.mockito.version>2.11.0</org.mockito.version>
5759
<org.slf4j.version>1.7.25</org.slf4j.version>
5860
<org.apache.maven.maven-plugin-annotations.version>3.5</org.apache.maven.maven-plugin-annotations.version>
59-
<org.apache.maven.version>3.5.0</org.apache.maven.version>
61+
<org.apache.maven.version>3.6.0</org.apache.maven.version>
6062
<io.openapitools.jackson.dataformat.version>1.0.4</io.openapitools.jackson.dataformat.version>
6163
<org.apache.maven.plugin-testing.version>3.3.0</org.apache.maven.plugin-testing.version>
6264
<javax.xml.bin.jaxb-api.version>2.3.0</javax.xml.bin.jaxb-api.version>
@@ -106,6 +108,19 @@
106108
<optional>true</optional>
107109
</dependency>
108110

111+
<!-- jackson version references from swagger has vulnerability -->
112+
<dependency>
113+
<groupId>com.fasterxml.jackson.core</groupId>
114+
<artifactId>jackson-databind</artifactId>
115+
<version>${com.fasterxml.jackson.core.version}</version>
116+
</dependency>
117+
<!-- guava 20.0 has vulnerability -->
118+
<dependency>
119+
<groupId>com.google.guava</groupId>
120+
<artifactId>guava</artifactId>
121+
<version>${com.google.guava.version}</version>
122+
</dependency>
123+
109124
<dependency>
110125
<groupId>junit</groupId>
111126
<artifactId>junit</artifactId>

0 commit comments

Comments
 (0)