Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

NOTE: This page is copy of /wiki/spaces/SV/pages/16094118 report

The tables contain the recommended package version upgrades for outdated direct dependencies with Critical or Severe vulnerabilities identified by NexusIQ. These packages must be upgraded by M2/M3 or a request for a waiver must be requested from SECCOM and the TSC.

  • Priority 1 recommendations have at least one Critical vulnerability.
  • Priority 2 recommendations contain at least one Severe vulnerability, and no Critical vulnerabilities.
  • There are four status values:
    • Status
      titleOpen
      - required upgrade identified
    • Status
      colourBlue
      titleIn Progress
       - project working on the upgrade
    • Status
      colourGreen
      titleComplete
      - package has been upgraded to the recommended version
    • Status
      colourYellow
      titleWaiver
      - project granted a waiver for the upgrade because of technical or resource constraints

When the upgrade of the package is complete change the status in the table to

Status
colourGreen
titleComplete
.

If a waiver is granted, change the status to

Status
colourYellow
titleWaiver
.

When the status of all direct dependency replacements is

Status
colourGreen
titleComplete
or
Status
colourYellow
titleWaiver
, the Jira ticket should be closed.

so-adapters-so-etsi-sol003-adapter

Status

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

Status
colourGreen
titleComplete

1com.fasterxml.jackson.core : jackson-databind : 2.11.32.14.1

This is indirect dependency coming from the o-parent.


 
There is no o-parent dependency present in the pom.xml 

 

Status
colourBlue
titleIn Progress

1org.yaml : snakeyaml : 1.261.33

This needs further analysis and is being checked in detail. We have a resource crunch at the moment.

 
That version is declare but there is no use in the entire file.

so-libs

Status

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

Status
colourGreen
titleComplete

1com.fasterxml.jackson.core : jackson-databind : 2.11.12.14.1

This is indirect dependency coming from the o-parent. 

 
The version 
2.14.2 is updated and available in Master branch 

so

Status

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

Status
colourGreen
titleComplete

1com.fasterxml.jackson.core : jackson-databind : 2.11.32.14.1

7

7

7

7


This is indirect dependency coming from the o-parent.


The version 2.14.2 is updated and available in Master branch   

Status
colourGreen
titleComplete

1com.fasterxml.jackson.core : jackson-databind : 2.9.82.14.1
7

Same as above
7

Status

7

colour

7

Blue

7

Same as above

titleIn Progress

1com.google.protobuf : protobuf-java : 3.10.04.0.0-rc-2

7

7

5


This needs further analysis and is being checked in detail. We have a resource crunch at the moment.

 
this dependency not found in Master branch 

Status
colourBlue
titleIn Progress

1com.h2database : h2 : 1.4.2000.16.4

9

9

8

8

6


We dont use this code in the production and is only built for testing code.


 
not found

Status
colourBlue
titleIn Progress

1org.apache.tomcat : tomcat-catalina : 9.0.459.0.37.1

7

6

This needs further analysis and We are facing resource issue at the moment, request a waiver.


 
this dependency not found in Master branch 


Status
colourGreen
titleComplete

1org.json : json : 2014010720220924

7


The change would bring in a major testing to be performed across the projects and we have a resource crunch.


 
The version 20220924 is updated and available in Master branch   

 

Status
colourGreen
titleComplete

1org.json : json : 2016021220220924
7

The change would bring in a major testing to be performed across the projects and we have a resource crunch.


 
The version 20220924 is updated and available in Master branch   

 

Status
colourBlue
titleIn Progress

1org.springframework : spring-web : 5.2.14.RELEASE6.0.2

9

7

4


The change would bring in a major testing to be performed across the projects and we have a resource crunch

.
 
this dependency not found in Master branch 


Status
colourBlue
titleIn Progress

1

org.springframework.data : spring-data-rest-hal-browser : 3.3.9.RELEASE

3.3.9.RELEASE

7

7

6

6

6

6

6

6

6

6

6

6

5

5

This needs further analysis and We are facing resource issue at the moment, request a waiver.


 
this dependency not found in Master branch 


Status
colourBlue
titleIn Progress

1org.springframework.security : spring-security-web : 5.4.63.0.11-oss

9


This needs further analysis and We are facing resource issue at the moment, request a waiver.


 
this dependency not found in Master branch 


Status
colourBlue
titleIn Progress

1org.yaml : snakeyaml : 1.261.33

7

6

6

6

6

5


This needs further analysis and We are facing resource issue at the moment, request a waiver.

Status
colourBlue
titleIn Progress

2org.glassfish.jersey.core : jersey-common : 2.22.1
5


Indirect dependency,

 
this dependency not found in Master branch 

Status
colourBlue
titleIn Progress

2org.glassfish.jersey.core : jersey-common : 2.30.1
5


Indirect dependency.


 
this dependency not found in Master branch 

Status
colourBlue
titleIn Progress

2org.springframework : spring-webmvc : 5.2.12.RELEASE6.0.2
4

This needs further analysis and We are facing resource issue at the moment, request a waiver.


 


this dependency not found in Master branch 

so-so-admin-cockpit

Status

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

Status
colourGreen
titleComplete

1com.fasterxml.jackson.core : jackson-databind : 2.11.12.14.1

This is indirect dependency coming from the o-parent. The change would bring in a major testing to be performed across the projects and we have a resource crunch

.
 


There is no o-parent dependency present in the pom.xml 

so-so-etsi-nfvo

Status

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

Status
colourGreen
titleComplete
1com.fasterxml.jackson.core : jackson-databind : 2.11.12.14.1

This is indirect dependency coming from the o-parent. The change would bring in a major testing to be performed across the projects and we have a resource crunch.


 
There is no o-parent dependency present in the pom.xml 


Status
colourBlue
titleIn Progress

1org.yaml : snakeyaml : 1.261.33

This needs further analysis and is being checked in detail. We have a resource crunch at the moment

.
 
That version is declare but there is no use in the entire file

.