From 16f3cd481e62e16e75593f4290c9e8da0e61a2d9 Mon Sep 17 00:00:00 2001 From: Amardeepsingh Siglani Date: Mon, 21 Jul 2025 15:51:21 -0700 Subject: [PATCH] updated commons-validator to fix CVE with commons-beansutils Signed-off-by: Amardeepsingh Siglani --- core/build.gradle | 11 +---------- 1 file changed, 1 insertion(+), 10 deletions(-) diff --git a/core/build.gradle b/core/build.gradle index cfce74c42..243b5ff8d 100644 --- a/core/build.gradle +++ b/core/build.gradle @@ -8,15 +8,6 @@ apply plugin: 'opensearch.java-rest-test' apply plugin: 'org.jetbrains.kotlin.jvm' apply plugin: 'jacoco' -configurations{ - all { - resolutionStrategy { - // force commons-beanutils to a non-vulnerable version - force "commons-beanutils:commons-beanutils:1.11.0" - } - } -} - dependencies { compileOnly "org.opensearch:opensearch:${opensearch_version}" implementation "org.jetbrains.kotlin:kotlin-stdlib:${kotlin_version}" @@ -25,7 +16,7 @@ dependencies { implementation "com.cronutils:cron-utils:9.1.7" api "org.opensearch.client:opensearch-rest-client:${opensearch_version}" api "org.opensearch:common-utils:${common_utils_version}@jar" - implementation 'commons-validator:commons-validator:1.7' + implementation 'commons-validator:commons-validator:1.10.0' testImplementation "org.opensearch.test:framework:${opensearch_version}" testImplementation "org.jetbrains.kotlin:kotlin-test:${kotlin_version}"