From 6e1ac518da3be513d5fca173b3cb6709cfde420f Mon Sep 17 00:00:00 2001 From: SkyeBeFreeman <928016560@qq.com> Date: Mon, 14 Mar 2022 15:39:39 +0800 Subject: [PATCH 1/2] fix:fix [Deserialization of Untrusted Data in logback](https://github.com/Tencent/spring-cloud-tencent/security/dependabot/1). --- pom.xml | 35 ++++++++++++------- .../polaris-circuitbreaker-example-a/pom.xml | 10 ++---- .../polaris-circuitbreaker-example-b/pom.xml | 10 ++---- 3 files changed, 27 insertions(+), 28 deletions(-) diff --git a/pom.xml b/pom.xml index 3848ac85..1bdf9d21 100644 --- a/pom.xml +++ b/pom.xml @@ -76,12 +76,23 @@ Hoxton.SR9 + + 1.2.7 + 0.8.3 3.2.0 1.2.7 + + + ch.qos.logback + logback-classic + ${logback.version} + + + @@ -232,16 +243,16 @@ - - - nexus-snapshots - https://oss.sonatype.org/content/repositories/snapshots/ - - false - - - true - - - + + + + + + + + + + + + \ No newline at end of file diff --git a/spring-cloud-tencent-examples/polaris-circuitbreaker-example/polaris-circuitbreaker-example-a/pom.xml b/spring-cloud-tencent-examples/polaris-circuitbreaker-example/polaris-circuitbreaker-example-a/pom.xml index 5bf16820..e365201e 100644 --- a/spring-cloud-tencent-examples/polaris-circuitbreaker-example/polaris-circuitbreaker-example-a/pom.xml +++ b/spring-cloud-tencent-examples/polaris-circuitbreaker-example/polaris-circuitbreaker-example-a/pom.xml @@ -1,6 +1,6 @@ - polaris-circuitbreaker-example @@ -17,12 +17,6 @@ - - ch.qos.logback - logback-core - 1.2.3 - compile - org.springframework.boot spring-boot-starter-web diff --git a/spring-cloud-tencent-examples/polaris-circuitbreaker-example/polaris-circuitbreaker-example-b/pom.xml b/spring-cloud-tencent-examples/polaris-circuitbreaker-example/polaris-circuitbreaker-example-b/pom.xml index 2c56070e..5042f175 100644 --- a/spring-cloud-tencent-examples/polaris-circuitbreaker-example/polaris-circuitbreaker-example-b/pom.xml +++ b/spring-cloud-tencent-examples/polaris-circuitbreaker-example/polaris-circuitbreaker-example-b/pom.xml @@ -1,6 +1,6 @@ - polaris-circuitbreaker-example @@ -17,12 +17,6 @@ - - ch.qos.logback - logback-core - 1.2.3 - compile - org.springframework.boot spring-boot-starter-webflux From bbe6a104e2d875dde6aa46925c10d714b5fb9324 Mon Sep 17 00:00:00 2001 From: SkyeBeFreeman <928016560@qq.com> Date: Mon, 14 Mar 2022 16:23:04 +0800 Subject: [PATCH 2/2] fix:fix dependencies error. --- pom.xml | 24 ++++++++++++------------ 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/pom.xml b/pom.xml index 1bdf9d21..6cd19bea 100644 --- a/pom.xml +++ b/pom.xml @@ -243,16 +243,16 @@ - - - - - - - - - - - - + + + nexus-snapshots + https://oss.sonatype.org/content/repositories/snapshots/ + + false + + + true + + + \ No newline at end of file