From 8724f13a5c59499e389fef9129b23ca3ffbf7688 Mon Sep 17 00:00:00 2001 From: rickchoijd Date: Tue, 21 Jan 2025 10:19:33 +0000 Subject: [PATCH] [ESWE-1205] Fix CVE; exclude testing dependency exclude `swagger-parser-safe-url-resolver` from integration test (via `swagger-parser`) --- build.gradle.kts | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/build.gradle.kts b/build.gradle.kts index c893384..b157b39 100644 --- a/build.gradle.kts +++ b/build.gradle.kts @@ -34,8 +34,9 @@ testing { kotlin.target.compilations { named("integrationTest") { associateWith(getByName("main")) } } implementation("uk.gov.justice.service.hmpps:hmpps-kotlin-spring-boot-starter-test:1.1.1") implementation("org.wiremock:wiremock-standalone:3.9.2") - implementation("io.swagger.parser.v3:swagger-parser:2.1.24") { + implementation("io.swagger.parser.v3:swagger-parser:2.1.25") { exclude(group = "io.swagger.core.v3") + exclude(group = "io.swagger.parser.v3", module = "swagger-parser-safe-url-resolver") } }