NIFI-10923 This closes #6745. Upgraded Apache SSHD to 2.9.2

Signed-off-by: Joe Witt <joewitt@apache.org>
This commit is contained in:
exceptionfactory 2022-12-01 12:40:54 -06:00 committed by Joe Witt
parent c3b0e1a790
commit 3399d09c46
No known key found for this signature in database
GPG Key ID: 9093BF854F811A1A
3 changed files with 17 additions and 2 deletions

View File

@ -35,6 +35,7 @@
<properties> <properties>
<yammer.metrics.version>2.2.0</yammer.metrics.version> <yammer.metrics.version>2.2.0</yammer.metrics.version>
<jolt.version>0.1.7</jolt.version> <jolt.version>0.1.7</jolt.version>
<org.apache.sshd.version>2.9.2</org.apache.sshd.version>
</properties> </properties>
<dependencyManagement> <dependencyManagement>
<dependencies> <dependencies>
@ -303,12 +304,12 @@
<dependency> <dependency>
<groupId>org.apache.sshd</groupId> <groupId>org.apache.sshd</groupId>
<artifactId>sshd-core</artifactId> <artifactId>sshd-core</artifactId>
<version>2.8.0</version> <version>${org.apache.sshd.version}</version>
</dependency> </dependency>
<dependency> <dependency>
<groupId>org.apache.sshd</groupId> <groupId>org.apache.sshd</groupId>
<artifactId>sshd-sftp</artifactId> <artifactId>sshd-sftp</artifactId>
<version>2.8.0</version> <version>${org.apache.sshd.version}</version>
</dependency> </dependency>
<dependency> <dependency>
<groupId>com.google.guava</groupId> <groupId>com.google.guava</groupId>

View File

@ -43,6 +43,7 @@
<groovy.eclipse.compiler.version>3.4.0-01</groovy.eclipse.compiler.version> <groovy.eclipse.compiler.version>3.4.0-01</groovy.eclipse.compiler.version>
<jaxb.version>2.3.2</jaxb.version> <jaxb.version>2.3.2</jaxb.version>
<jgit.version>5.13.1.202206130422-r</jgit.version> <jgit.version>5.13.1.202206130422-r</jgit.version>
<org.apache.sshd.version>2.9.2</org.apache.sshd.version>
</properties> </properties>
<dependencyManagement> <dependencyManagement>
@ -241,6 +242,17 @@
</exclusion> </exclusion>
</exclusions> </exclusions>
</dependency> </dependency>
<!-- Override transitive SSHD version from JGit -->
<dependency>
<groupId>org.apache.sshd</groupId>
<artifactId>sshd-osgi</artifactId>
<version>${org.apache.sshd.version}</version>
</dependency>
<dependency>
<groupId>org.apache.sshd</groupId>
<artifactId>sshd-sftp</artifactId>
<version>${org.apache.sshd.version}</version>
</dependency>
</dependencies> </dependencies>
</dependencyManagement> </dependencyManagement>

View File

@ -970,6 +970,8 @@
<exclude>org.bouncycastle:bcpkix-jdk15on</exclude> <exclude>org.bouncycastle:bcpkix-jdk15on</exclude>
<exclude>org.bouncycastle:bcutil-jdk15on</exclude> <exclude>org.bouncycastle:bcutil-jdk15on</exclude>
<exclude>org.bouncycastle:bcmail-jdk15on</exclude> <exclude>org.bouncycastle:bcmail-jdk15on</exclude>
<!-- Exclude SSHD 2.9.1 and earlier due to CVE-2022-45047 -->
<exclude>org.apache.sshd:*:[,2.9.1]</exclude>
</excludes> </excludes>
<includes> <includes>
<!-- Versions of JSR305 after 3.0.1 are allowed https://github.com/findbugsproject/findbugs/issues/128 --> <!-- Versions of JSR305 after 3.0.1 are allowed https://github.com/findbugsproject/findbugs/issues/128 -->