Skip to content

Commit 4103d18

Browse files
committed
fix vulnerabilities on backend
1 parent 2a53cf9 commit 4103d18

File tree

2 files changed

+8
-0
lines changed

2 files changed

+8
-0
lines changed

src/backend/Dockerfile.efiling-api

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -41,6 +41,8 @@ RUN mvn -B clean install \
4141
#############################################################################################
4242
FROM eclipse-temurin:17-jre-alpine
4343

44+
RUN apk update && apk add --upgrade --no-cache libexpat # fix CVE-2024-8176
45+
4446
# ARG MVN_PROFILES
4547
ARG SERVICE_NAME=efiling-api
4648

src/backend/efiling-api/pom.xml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -208,6 +208,7 @@
208208
<dependency>
209209
<groupId>org.apache.tomcat.embed</groupId>
210210
<artifactId>tomcat-embed-core</artifactId>
211+
<version>10.1.39</version>
211212
</dependency>
212213
<dependency>
213214
<groupId>org.json</groupId>
@@ -243,6 +244,11 @@
243244
<artifactId>cxf-core</artifactId>
244245
<version>4.0.6</version>
245246
</dependency>
247+
<dependency>
248+
<groupId>org.springframework.security</groupId>
249+
<artifactId>spring-security-crypto</artifactId>
250+
<version>6.3.8</version>
251+
</dependency>
246252
</dependencies>
247253

248254
<dependencyManagement>

0 commit comments

Comments
 (0)