Improve commons-fileupload override method (#2815)

Signed-off-by: Avgustin Marinov <Avgustin.Marinov@bosch.com>
This commit is contained in:
Avgustin Marinov
2025-11-18 11:13:14 +02:00
committed by GitHub
parent d09f782de8
commit 5011641789
2 changed files with 10 additions and 11 deletions

View File

@@ -24,18 +24,7 @@
<name>hawkBit :: SDK :: Commons</name>
<description>SDK commons</description>
<properties>
<commons.fileupload.version>1.6.0</commons.fileupload.version>
</properties>
<dependencies>
<!-- Override vulnerable feign-form-spring dependency on commons-fileupload -->
<dependency>
<groupId>commons-fileupload</groupId>
<artifactId>commons-fileupload</artifactId>
<version>${commons.fileupload.version}</version>
</dependency>
<dependency>
<groupId>org.springframework.cloud</groupId>
<artifactId>spring-cloud-starter-openfeign</artifactId>

10
pom.xml
View File

@@ -48,6 +48,9 @@
as libraries in other projects might be compiled with a different, lower, java version. -->
<java.client.version>17</java.client.version>
<!-- Override vulnerable commons-fileupload used by feign-form-spring (via spring-cloud-starter-openfeign) -->
<commons-fileupload.version>1.6.0</commons-fileupload.version>
<!-- must be the same as the parent version -->
<spring.boot.version>3.5.7</spring.boot.version>
<spring.cloud.version>2025.0.0</spring.cloud.version>
@@ -198,6 +201,13 @@
<dependencyManagement>
<dependencies>
<!-- Override vulnerable commons-fileupload used by feign-form-spring (via spring-cloud-starter-openfeign) -->
<dependency>
<groupId>commons-fileupload</groupId>
<artifactId>commons-fileupload</artifactId>
<version>${commons-fileupload.version}</version>
</dependency>
<!-- Misc -->
<dependency>
<groupId>com.rabbitmq</groupId>