Files
conductor-oss--conductor/springboot-bom-overrides.gradle
Viren Baraiya 8f78c0a781 Resolve #1490: CVEs detected in Conductor-OSS 3.32.0-rc.23 dependencies (#1502)
* conductor workspace baseline [conductor-workspace:6589c18f-c889-4d2a-b5d8-08a22da1c609:baseline]

Conductor-Original-Branch: main
Conductor-Original-Head: 4799963183

* code_subtask secure-bom-transitives

* code_subtask align-kafka-event-queue

* code_subtask upgrade-direct-libraries

* code_subtask upgrade-boot-jackson

---------

Co-authored-by: Naomi Most <naomi.most@orkes.io>
2026-08-10 09:53:34 -07:00

48 lines
2.2 KiB
Groovy

/*
* Copyright 2023 Conductor authors
* <p>
* Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with
* the License. You may obtain a copy of the License at
* <p>
* http://www.apache.org/licenses/LICENSE-2.0
* <p>
* Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on
* an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the
* specific language governing permissions and limitations under the License.
*/
// Contains overrides for Spring Boot Dependency Management plugin
// Spring Boot documents supported dependency version override properties at
// https://docs.spring.io/spring-boot/3.3/appendix/dependency-versions/properties.html.
// Keep server runtime dependencies on patched versions until the Spring Boot BOM includes them.
ext['spring-framework.version'] = '6.2.19'
ext['spring-security.version'] = '6.5.11'
ext['log4j2.version'] = '2.25.4'
ext['netty.version'] = '4.1.135.Final'
ext['kafka.version'] = '3.9.1'
// Conductor's default is ES6, but SB brings in ES7
ext['elasticsearch.version'] = revElasticSearch7
// When building with ES8 persistence, override Spring Boot's managed Elasticsearch versions.
// Spring Boot 3.3.x manages `org.elasticsearch.client:elasticsearch-rest-client` via
// `elasticsearch.version` and `co.elastic.clients:elasticsearch-java` via
// `elasticsearch-client.version`.
def indexingBackend = findProperty('indexingBackend') ?: 'elasticsearch'
if (indexingBackend == 'elasticsearch8' || indexingBackend == 'es8') {
ext['elasticsearch.version'] = revElasticSearch8
ext['elasticsearch-client.version'] = revElasticSearch8
}
// SB brings groovy 3.0.x which is not compatible with Spock
ext['groovy.version'] = revGroovy
// Keep Testcontainers aligned across modules instead of Spring Boot BOM defaults.
ext['testcontainers.version'] = revTestContainer
// Prevent Spring Boot BOM from downgrading Jedis. Modules that need jedis depend on
// conductor-redis-api (which declares jedis as 'api'), and without this override the
// dependency-management plugin would resolve the BOM version instead of 6.0.0.
ext['jedis.version'] = revJedis