Skip to content

Commit

Permalink
Update Jetty dependency. (#4141)
Browse files Browse the repository at this point in the history
9.4.51 needs to be updated due to
- https://nvd.nist.gov/vuln/detail/CVE-2023-40167
- https://security.snyk.io/vuln/SNYK-JAVA-ORGECLIPSEJETTY-5958847

Co-authored-by: Anup Ghatage <[email protected]>
(cherry picked from commit c1b7f76)
  • Loading branch information
Ghatage authored and zymap committed Dec 7, 2023
1 parent 2c204b7 commit 58e53f7
Show file tree
Hide file tree
Showing 5 changed files with 31 additions and 31 deletions.
14 changes: 7 additions & 7 deletions bookkeeper-dist/src/main/resources/LICENSE-all.bin.txt
Original file line number Diff line number Diff line change
Expand Up @@ -257,13 +257,13 @@ Apache Software License, Version 2.
- lib/org.apache.zookeeper-zookeeper-3.8.0.jar [21]
- lib/org.apache.zookeeper-zookeeper-jute-3.8.0.jar [21]
- lib/org.apache.zookeeper-zookeeper-3.8.0-tests.jar [21]
- lib/org.eclipse.jetty-jetty-http-9.4.51.v20230217.jar [22]
- lib/org.eclipse.jetty-jetty-io-9.4.51.v20230217.jar [22]
- lib/org.eclipse.jetty-jetty-security-9.4.51.v20230217.jar [22]
- lib/org.eclipse.jetty-jetty-server-9.4.51.v20230217.jar [22]
- lib/org.eclipse.jetty-jetty-servlet-9.4.51.v20230217.jar [22]
- lib/org.eclipse.jetty-jetty-util-9.4.51.v20230217.jar [22]
- lib/org.eclipse.jetty-jetty-util-ajax-9.4.51.v20230217.jar [22]
- lib/org.eclipse.jetty-jetty-http-9.4.53.v20231009.jar [22]
- lib/org.eclipse.jetty-jetty-io-9.4.53.v20231009.jar [22]
- lib/org.eclipse.jetty-jetty-security-9.4.53.v20231009.jar [22]
- lib/org.eclipse.jetty-jetty-server-9.4.53.v20231009.jar [22]
- lib/org.eclipse.jetty-jetty-servlet-9.4.53.v20231009.jar [22]
- lib/org.eclipse.jetty-jetty-util-9.4.53.v20231009.jar [22]
- lib/org.eclipse.jetty-jetty-util-ajax-9.4.53.v20231009.jar [22]
- lib/org.rocksdb-rocksdbjni-6.29.4.1.jar [23]
- lib/com.beust-jcommander-1.82.jar [24]
- lib/com.yahoo.datasketches-memory-0.8.3.jar [25]
Expand Down
14 changes: 7 additions & 7 deletions bookkeeper-dist/src/main/resources/LICENSE-server.bin.txt
Original file line number Diff line number Diff line change
Expand Up @@ -257,13 +257,13 @@ Apache Software License, Version 2.
- lib/org.apache.zookeeper-zookeeper-3.8.0.jar [21]
- lib/org.apache.zookeeper-zookeeper-jute-3.8.0.jar [21]
- lib/org.apache.zookeeper-zookeeper-3.8.0-tests.jar [21]
- lib/org.eclipse.jetty-jetty-http-9.4.51.v20230217.jar [22]
- lib/org.eclipse.jetty-jetty-io-9.4.51.v20230217.jar [22]
- lib/org.eclipse.jetty-jetty-security-9.4.51.v20230217.jar [22]
- lib/org.eclipse.jetty-jetty-server-9.4.51.v20230217.jar [22]
- lib/org.eclipse.jetty-jetty-servlet-9.4.51.v20230217.jar [22]
- lib/org.eclipse.jetty-jetty-util-9.4.51.v20230217.jar [22]
- lib/org.eclipse.jetty-jetty-util-ajax-9.4.51.v20230217.jar [22]
- lib/org.eclipse.jetty-jetty-http-9.4.53.v20231009.jar [22]
- lib/org.eclipse.jetty-jetty-io-9.4.53.v20231009.jar [22]
- lib/org.eclipse.jetty-jetty-security-9.4.53.v20231009.jar [22]
- lib/org.eclipse.jetty-jetty-server-9.4.53.v20231009.jar [22]
- lib/org.eclipse.jetty-jetty-servlet-9.4.53.v20231009.jar [22]
- lib/org.eclipse.jetty-jetty-util-9.4.53.v20231009.jar [22]
- lib/org.eclipse.jetty-jetty-util-ajax-9.4.53.v20231009.jar [22]
- lib/org.rocksdb-rocksdbjni-6.29.4.1.jar [23]
- lib/com.beust-jcommander-1.82.jar [24]
- lib/com.yahoo.datasketches-memory-0.8.3.jar [25]
Expand Down
16 changes: 8 additions & 8 deletions bookkeeper-dist/src/main/resources/NOTICE-all.bin.txt
Original file line number Diff line number Diff line change
Expand Up @@ -86,13 +86,13 @@ SoundCloud Ltd. (http://soundcloud.com/).
This product includes software developed as part of the
Ocelli project by Netflix Inc. (https://github.com/Netflix/ocelli/).
------------------------------------------------------------------------------------
- lib/org.eclipse.jetty-jetty-http-9.4.51.v20230217.jar
- lib/org.eclipse.jetty-jetty-io-9.4.51.v20230217.jar
- lib/org.eclipse.jetty-jetty-security-9.4.51.v20230217.jar
- lib/org.eclipse.jetty-jetty-server-9.4.51.v20230217.jar
- lib/org.eclipse.jetty-jetty-servlet-9.4.51.v20230217.jar
- lib/org.eclipse.jetty-jetty-util-9.4.51.v20230217.jar
- lib/org.eclipse.jetty-jetty-util-ajax-9.4.51.v20230217.jar
- lib/org.eclipse.jetty-jetty-http-9.4.53.v20231009.jar
- lib/org.eclipse.jetty-jetty-io-9.4.53.v20231009.jar
- lib/org.eclipse.jetty-jetty-security-9.4.53.v20231009.jar
- lib/org.eclipse.jetty-jetty-server-9.4.53.v20231009.jar
- lib/org.eclipse.jetty-jetty-servlet-9.4.53.v20231009.jar
- lib/org.eclipse.jetty-jetty-util-9.4.53.v20231009.jar
- lib/org.eclipse.jetty-jetty-util-ajax-9.4.53.v20231009.jar

==============================================================
Jetty Web Container
Expand All @@ -114,7 +114,7 @@ Jetty is dual licensed under both

Jetty may be distributed under either license.

lib/org.eclipse.jetty-jetty-util-9.4.51.v20230217.jar bundles UnixCrypt
lib/org.eclipse.jetty-jetty-util-9.4.53.v20231009.jar bundles UnixCrypt

The UnixCrypt.java code implements the one way cryptography used by
Unix systems for simple password protection. Copyright 1996 Aki Yoshida,
Expand Down
16 changes: 8 additions & 8 deletions bookkeeper-dist/src/main/resources/NOTICE-server.bin.txt
Original file line number Diff line number Diff line change
Expand Up @@ -68,13 +68,13 @@ SoundCloud Ltd. (http://soundcloud.com/).
This product includes software developed as part of the
Ocelli project by Netflix Inc. (https://github.com/Netflix/ocelli/).
------------------------------------------------------------------------------------
- lib/org.eclipse.jetty-jetty-http-9.4.51.v20230217.jar
- lib/org.eclipse.jetty-jetty-io-9.4.51.v20230217.jar
- lib/org.eclipse.jetty-jetty-security-9.4.51.v20230217.jar
- lib/org.eclipse.jetty-jetty-server-9.4.51.v20230217.jar
- lib/org.eclipse.jetty-jetty-servlet-9.4.51.v20230217.jar
- lib/org.eclipse.jetty-jetty-util-9.4.51.v20230217.jar
- lib/org.eclipse.jetty-jetty-util-ajax-9.4.51.v20230217.jar
- lib/org.eclipse.jetty-jetty-http-9.4.53.v20231009.jar
- lib/org.eclipse.jetty-jetty-io-9.4.53.v20231009.jar
- lib/org.eclipse.jetty-jetty-security-9.4.53.v20231009.jar
- lib/org.eclipse.jetty-jetty-server-9.4.53.v20231009.jar
- lib/org.eclipse.jetty-jetty-servlet-9.4.53.v20231009.jar
- lib/org.eclipse.jetty-jetty-util-9.4.53.v20231009.jar
- lib/org.eclipse.jetty-jetty-util-ajax-9.4.53.v20231009.jar

==============================================================
Jetty Web Container
Expand All @@ -96,7 +96,7 @@ Jetty is dual licensed under both

Jetty may be distributed under either license.

lib/org.eclipse.jetty-jetty-util-9.4.51.v20230217.jar bundles UnixCrypt
lib/org.eclipse.jetty-jetty-util-9.4.53.v20231009.jar bundles UnixCrypt

The UnixCrypt.java code implements the one way cryptography used by
Unix systems for simple password protection. Copyright 1996 Aki Yoshida,
Expand Down
2 changes: 1 addition & 1 deletion pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -143,7 +143,7 @@
<hdrhistogram.version>2.1.10</hdrhistogram.version>
<jackson.version>2.13.4.20221013</jackson.version>
<jcommander.version>1.82</jcommander.version>
<jetty.version>9.4.51.v20230217</jetty.version>
<jetty.version>9.4.53.v20231009</jetty.version>
<jmh.version>1.19</jmh.version>
<jmock.version>2.8.2</jmock.version>
<jsoup.version>1.14.3</jsoup.version>
Expand Down

0 comments on commit 58e53f7

Please sign in to comment.