Skip to end of metadata
Go to start of metadata

You are viewing an old version of this content. View the current version.

Compare with Current View Version History

« Previous Version 4 Next »

Please note: Report is as per London release

so-adapters-so-etsi-sol003-adapter

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

1com.fasterxml.jackson.core : jackson-databind : 2.11.32.14.1

This is indirect dependency coming from the o-parent.
 
There is no o-parent dependency present in the pom.xml 

1org.yaml : snakeyaml : 1.261.33

This needs further analysis and is being checked in detail. We have a resource crunch at the moment.

 
That version is declare but there is no use in the entire file.

so-libs

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

1com.fasterxml.jackson.core : jackson-databind : 2.11.12.14.1

This is indirect dependency coming from the o-parent. 

 
The version 
2.14.2 is updated and available in Master branch 

so

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

1com.fasterxml.jackson.core : jackson-databind : 2.11.32.14.1

7

7

7

7

This is indirect dependency coming from the o-parent.

The version 2.14.2 is updated and available in Master branch   

1com.fasterxml.jackson.core : jackson-databind : 2.9.82.14.1

7

7

7

7

7

Same as above
1com.google.protobuf : protobuf-java : 3.10.04.0.0-rc-2

7

7

5

This needs further analysis and is being checked in detail. We have a resource crunch at the moment.

 
not found 

1com.h2database : h2 : 1.4.2000.16.4

9

9

8

8

6

We dont use this code in the production and is only built for testing code.

 
not found

1org.apache.tomcat : tomcat-catalina : 9.0.459.0.37.1

7

6

This needs further analysis and We are facing resource issue at the moment, request a waiver.
 
not found

1org.json : json : 2014010720220924

7

The change would bring in a major testing to be performed across the projects and we have a resource crunch.

 
The version 20220924 is updated and available in Master branch   

1org.json : json : 20160212202209247

The change would bring in a major testing to be performed across the projects and we have a resource crunch.
 
The version 20220924 is updated and available in Master branch   

1org.springframework : spring-web : 5.2.14.RELEASE6.0.2

9

7

4

The change would bring in a major testing to be performed across the projects and we have a resource crunch.
 
not found

1

org.springframework.data : spring-data-rest-hal-browser : 3.3.9.RELEASE

3.3.9.RELEASE

7

7

6

6

6

6

6

6

6

6

6

6

5

5

This needs further analysis and We are facing resource issue at the moment, request a waiver.

 
not found

1org.springframework.security : spring-security-web : 5.4.63.0.11-oss

9

This needs further analysis and We are facing resource issue at the moment, request a waiver.
 
not found

1org.yaml : snakeyaml : 1.261.33

7

6

6

6

6

5

This needs further analysis and We are facing resource issue at the moment, request a waiver.

2org.glassfish.jersey.core : jersey-common : 2.22.1
5

Indirect dependency,
 
not found

2org.glassfish.jersey.core : jersey-common : 2.30.1
5

Indirect dependency.
 
not found

2org.springframework : spring-webmvc : 5.2.12.RELEASE6.0.24

This needs further analysis and We are facing resource issue at the moment, request a waiver.
 
not found 

so-so-admin-cockpit

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

1com.fasterxml.jackson.core : jackson-databind : 2.11.12.14.1

This is indirect dependency coming from the o-parent. The change would bring in a major testing to be performed across the projects and we have a resource crunch.

 
There is no o-parent dependency present in the pom.xml 

so-so-etsi-nfvo

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

1com.fasterxml.jackson.core : jackson-databind : 2.11.12.14.1

This is indirect dependency coming from the o-parent. The change would bring in a major testing to be performed across the projects and we have a resource crunch.
 
There is no o-parent dependency present in the pom.xml 

1org.yaml : snakeyaml : 1.261.33

This needs further analysis and is being checked in detail. We have a resource crunch at the moment.
 
That version is declare but there is no use in the entire file.

  • No labels