From 18e5f3cc09cfabf11a30c5a7004c5fb6c280c933 Mon Sep 17 00:00:00 2001 From: Adam Rauch Date: Tue, 29 Jul 2025 20:28:59 -0700 Subject: [PATCH 1/3] Update dependencies --- gradle.properties | 34 +++++++++++++++++----------------- 1 file changed, 17 insertions(+), 17 deletions(-) diff --git a/gradle.properties b/gradle.properties index c231549dea..74c0de7cb5 100644 --- a/gradle.properties +++ b/gradle.properties @@ -125,21 +125,21 @@ commonsBeanutilsVersion=1.11.0 commonsCodecVersion=1.18.0 commonsCollections4Version=4.5.0 commonsCollectionsVersion=3.2.2 -commonsCompressVersion=1.27.1 +commonsCompressVersion=1.28.0 commonsDbcpVersion=1.4 commonsDigesterVersion=1.8.1 commonsDiscoveryVersion=0.2 -commonsIoVersion=2.19.0 +commonsIoVersion=2.20.0 commonsLang3Version=3.18.0 commonsLangVersion=2.6 commonsLoggingVersion=1.3.5 commonsMath3Version=3.6.1 commonsPoolVersion=1.6 commonsTextVersion=1.13.1 -commonsValidatorVersion=1.9.0 +commonsValidatorVersion=1.10.0 commonsVfs2Version=2.10.0 -datadogVersion=1.50.0 +datadogVersion=1.51.2 dom4jVersion=2.1.4 @@ -155,8 +155,8 @@ fopVersion=2.11 # Force latest for consistency googleAutoValueAnnotationsVersion=1.10.4 -googleErrorProneAnnotationsVersion=2.38.0 -googleHttpClientVersion=1.47.0 +googleErrorProneAnnotationsVersion=2.41.0 +googleHttpClientVersion=1.47.1 googleOauthClientVersion=1.39.0 googleProtocolBufVersion=3.25.8 @@ -192,10 +192,10 @@ httpcoreVersion=4.4.16 intellijKotlinVersion=1.9.10 # Update all Jackson dependency versions below in tandem, unless one gets a patch release out-of-sync with the others -jacksonVersion=2.19.1 -jacksonAnnotationsVersion=2.19.1 -jacksonDatabindVersion=2.19.1 -jacksonJaxrsBaseVersion=2.19.1 +jacksonVersion=2.19.2 +jacksonAnnotationsVersion=2.19.2 +jacksonDatabindVersion=2.19.2 +jacksonJaxrsBaseVersion=2.19.2 # The Jakarta Activation API version that Angus Activation implements. Keep in sync with angusActivationVersion (above). jakartaActivationApiVersion=2.1.3 @@ -230,7 +230,7 @@ jsr305Version=3.0.2 orgJsonVersion=20250517 -jsoupVersion=1.20.1 +jsoupVersion=1.21.1 junitVersion=4.13.2 @@ -238,7 +238,7 @@ jxlVersion=2.6.3 kaptchaVersion=2.3 -log4j2Version=2.24.3 +log4j2Version=2.25.1 lombokVersion=1.18.38 @@ -247,7 +247,7 @@ luceneVersion=9.12.2 mssqlJdbcVersion=12.10.1.jre11 # force for docker -nettyVersion=4.2.2.Final +nettyVersion=4.2.3.Final objenesisVersion=1.0 @@ -284,12 +284,12 @@ slf4jLog4j12Version=2.0.17 slf4jLog4jApiVersion=2.0.17 # This is a dependency for HTSJDK. Force version for CVE-2023-43642 -snappyJavaVersion=1.1.10.7 +snappyJavaVersion=1.1.10.8 # Also, update apacheTomcatVersion above to match Spring Boot's Tomcat dependency version -springBootVersion=3.5.3 +springBootVersion=3.5.4 # This usually matches the Spring Framework version dictated by springBootVersion -springVersion=6.2.8 +springVersion=6.2.9 sqliteJdbcVersion=3.50.3.0 @@ -308,7 +308,7 @@ validationApiVersion=1.1.0.Final validationJakartaApiVersion=3.0.2 # NLP and SAML bring woodstox-core in as a transitive dependency but with very different versions. We force the later version. -woodstoxCoreVersion=7.1.0 +woodstoxCoreVersion=7.1.1 # saml and query bring in different versions transitively; we force the later one xalanVersion=2.7.2 From f3a3070c627941249259b9bda499cbb7013d1eb1 Mon Sep 17 00:00:00 2001 From: Adam Rauch Date: Tue, 29 Jul 2025 20:46:22 -0700 Subject: [PATCH 2/3] Update tika --- gradle.properties | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/gradle.properties b/gradle.properties index 74c0de7cb5..1bfb5c0dee 100644 --- a/gradle.properties +++ b/gradle.properties @@ -299,7 +299,7 @@ stax2ApiVersion=4.2.2 thumbnailatorVersion=0.4.20 # used for tika-core in API and tika-parsers in search -tikaVersion=3.2.0 +tikaVersion=3.2.1 # sync with Tika tukaaniXZVersion=1.10 From 962d254906a375073e5936b821c18a3be6e0a36b Mon Sep 17 00:00:00 2001 From: Adam Rauch Date: Wed, 30 Jul 2025 12:35:10 -0700 Subject: [PATCH 3/3] Back to log4j 2.24.3 since 2.25.0 & 2.25.1 generate harmless but annoying gradle errors. https://github.com/apache/logging-log4j2/issues/3779 --- gradle.properties | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/gradle.properties b/gradle.properties index 1bfb5c0dee..75c8e08540 100644 --- a/gradle.properties +++ b/gradle.properties @@ -238,7 +238,7 @@ jxlVersion=2.6.3 kaptchaVersion=2.3 -log4j2Version=2.25.1 +log4j2Version=2.24.3 lombokVersion=1.18.38