Skip to content

Commit 5a42961

Browse files
authored
chore: upgrade jetty version to 11.0.26 to fix CVE-2025-5115 (#138)
1 parent 03ae2ac commit 5a42961

6 files changed

Lines changed: 9 additions & 18 deletions

File tree

gradle/libs.versions.toml

Lines changed: 0 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,16 +1,11 @@
11
[versions]
2-
hypertrace-grpcutils = "0.13.14"
3-
jetty = "11.0.24"
4-
guice = "7.0.0"
52
dropwizard-metrics = "4.2.25"
63
micrometer = "1.14.4"
74
prometheus-simpleclient = "0.16.0"
85
caffeine = "3.1.8"
96

107
[libraries]
118
awaitility = { module = "org.awaitility:awaitility", version = "4.0.3" }
12-
hypertrace-grpcutils-server = { module = "org.hypertrace.core.grpcutils:grpc-server-utils", version.ref = "hypertrace-grpcutils" }
13-
grpc-services = { module = "io.grpc:grpc-services" }
149
jakarta-servlet-api = { module = "jakarta.servlet:jakarta.servlet-api", version = "6.0.0" }
1510
dropwizard-metrics-jakarta-servlet = { module = "io.dropwizard.metrics:metrics-jakarta-servlet", version.ref = "dropwizard-metrics" }
1611
dropwizard-metrics-jakarta-servlets = { module = "io.dropwizard.metrics:metrics-jakarta-servlets", version.ref = "dropwizard-metrics" }
@@ -21,11 +16,7 @@ micrometer-jvm-extras = { module = "io.github.mweirauch:micrometer-jvm-extras",
2116
prometheus-simpleclient-dropwizard = { module = "io.prometheus:simpleclient_dropwizard", version.ref = "prometheus-simpleclient" }
2217
prometheus-simpleclient-servlet-jakarta = { module = "io.prometheus:simpleclient_servlet_jakarta", version.ref = "prometheus-simpleclient" }
2318
prometheus-simpleclient-pushgateway = { module = "io.prometheus:simpleclient_pushgateway", version.ref = "prometheus-simpleclient" }
24-
jetty-servlet = { module = "org.eclipse.jetty:jetty-servlet", version.ref = "jetty" }
25-
jetty-server = { module = "org.eclipse.jetty:jetty-server", version.ref = "jetty" }
26-
jetty-servlets = { module = "org.eclipse.jetty:jetty-servlets", version.ref = "jetty" }
2719
caffeine = { module = "com.github.ben-manes.caffeine:caffeine", version.ref = "caffeine" }
28-
guice-servlet = { module = "com.google.inject.extensions:guice-servlet", version.ref = "guice" }
2920
apache-httpcomponents-httpclient = { module = "org.apache.httpcomponents:httpclient", version = "4.5.13" }
3021

3122
[plugins]

platform-grpc-service-framework/build.gradle.kts

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ plugins {
88
dependencies {
99
api(projects.platformServiceFramework)
1010
api(commonLibs.grpc.api)
11-
api(localLibs.grpc.services)
11+
api(commonLibs.grpc.services)
1212
api(commonLibs.hypertrace.grpcutils.client)
1313
api(commonLibs.typesafe.config)
1414
api(commonLibs.protobuf.java)
@@ -21,5 +21,5 @@ dependencies {
2121
implementation(commonLibs.grpc.inprocess)
2222
implementation(commonLibs.grpc.netty)
2323
implementation(commonLibs.slf4j2.api)
24-
implementation(localLibs.hypertrace.grpcutils.server)
24+
implementation(commonLibs.hypertrace.grpcutils.server)
2525
}

platform-http-service-framework/build.gradle.kts

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -13,11 +13,11 @@ dependencies {
1313

1414
implementation(projects.platformMetrics)
1515
implementation(commonLibs.slf4j2.api)
16-
implementation(localLibs.guice.servlet)
16+
implementation(commonLibs.guice.servlet)
1717
implementation(commonLibs.guava)
18-
implementation(localLibs.jetty.servlet)
19-
implementation(localLibs.jetty.server)
20-
implementation(localLibs.jetty.servlets)
18+
implementation(commonLibs.jetty.servlet)
19+
implementation(commonLibs.jetty.server)
20+
implementation(commonLibs.jetty.servlets)
2121
annotationProcessor(commonLibs.lombok)
2222
compileOnly(commonLibs.lombok)
2323
}

platform-metrics/build.gradle.kts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ dependencies {
2222
implementation(localLibs.prometheus.simpleclient.dropwizard)
2323
implementation(localLibs.prometheus.simpleclient.servlet.jakarta)
2424
implementation(localLibs.prometheus.simpleclient.pushgateway)
25-
implementation(localLibs.jetty.servlet)
25+
implementation(commonLibs.jetty.servlet)
2626
implementation(commonLibs.guava)
2727

2828
compileOnly(localLibs.caffeine)

platform-service-framework/build.gradle.kts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ dependencies {
1818

1919
// Use for thread dump servlet
2020
implementation(localLibs.dropwizard.metrics.jakarta.servlets)
21-
implementation(localLibs.jetty.servlet)
21+
implementation(commonLibs.jetty.servlet)
2222

2323
// Use for metrics servlet
2424
implementation(localLibs.prometheus.simpleclient.servlet.jakarta)

settings.gradle.kts

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ plugins {
1616
}
1717

1818
configure<DependencyPluginSettingExtension> {
19-
catalogVersion.set("0.3.51")
19+
catalogVersion.set("0.3.72")
2020
}
2121

2222
enableFeaturePreview("TYPESAFE_PROJECT_ACCESSORS")

0 commit comments

Comments
 (0)