From 18625952a9378d6e2b8aa156313d1c730476b085 Mon Sep 17 00:00:00 2001 From: Tianli Feng Date: Fri, 25 Jun 2021 13:18:15 -0700 Subject: [PATCH] update external library 'pdfbox' version to 2.0.24 to reduce vulnerability (#883) --- plugins/ingest-attachment/build.gradle | 2 +- plugins/ingest-attachment/licenses/fontbox-2.0.23.jar.sha1 | 1 - plugins/ingest-attachment/licenses/fontbox-2.0.24.jar.sha1 | 1 + plugins/ingest-attachment/licenses/pdfbox-2.0.23.jar.sha1 | 1 - plugins/ingest-attachment/licenses/pdfbox-2.0.24.jar.sha1 | 1 + 5 files changed, 3 insertions(+), 3 deletions(-) delete mode 100644 plugins/ingest-attachment/licenses/fontbox-2.0.23.jar.sha1 create mode 100644 plugins/ingest-attachment/licenses/fontbox-2.0.24.jar.sha1 delete mode 100644 plugins/ingest-attachment/licenses/pdfbox-2.0.23.jar.sha1 create mode 100644 plugins/ingest-attachment/licenses/pdfbox-2.0.24.jar.sha1 diff --git a/plugins/ingest-attachment/build.gradle b/plugins/ingest-attachment/build.gradle index 0b696b48cce..a31deb24fbb 100644 --- a/plugins/ingest-attachment/build.gradle +++ b/plugins/ingest-attachment/build.gradle @@ -39,7 +39,7 @@ opensearchplugin { versions << [ 'tika' : '1.24.1', - 'pdfbox': '2.0.23', + 'pdfbox': '2.0.24', 'poi' : '4.1.2', 'mime4j': '0.8.3' ] diff --git a/plugins/ingest-attachment/licenses/fontbox-2.0.23.jar.sha1 b/plugins/ingest-attachment/licenses/fontbox-2.0.23.jar.sha1 deleted file mode 100644 index eefdc9011f5..00000000000 --- a/plugins/ingest-attachment/licenses/fontbox-2.0.23.jar.sha1 +++ /dev/null @@ -1 +0,0 @@ -1a6b960dd2c1b1f8a5f5d6668b2930b50ff4324d \ No newline at end of file diff --git a/plugins/ingest-attachment/licenses/fontbox-2.0.24.jar.sha1 b/plugins/ingest-attachment/licenses/fontbox-2.0.24.jar.sha1 new file mode 100644 index 00000000000..1f638886791 --- /dev/null +++ b/plugins/ingest-attachment/licenses/fontbox-2.0.24.jar.sha1 @@ -0,0 +1 @@ +df8ecb3006dfcd52355a5902096e5ec34f06112e \ No newline at end of file diff --git a/plugins/ingest-attachment/licenses/pdfbox-2.0.23.jar.sha1 b/plugins/ingest-attachment/licenses/pdfbox-2.0.23.jar.sha1 deleted file mode 100644 index 43583d43b02..00000000000 --- a/plugins/ingest-attachment/licenses/pdfbox-2.0.23.jar.sha1 +++ /dev/null @@ -1 +0,0 @@ -b89643d162c4e30b4fe39cfa265546cc506d4d18 \ No newline at end of file diff --git a/plugins/ingest-attachment/licenses/pdfbox-2.0.24.jar.sha1 b/plugins/ingest-attachment/licenses/pdfbox-2.0.24.jar.sha1 new file mode 100644 index 00000000000..2eb2e357cbf --- /dev/null +++ b/plugins/ingest-attachment/licenses/pdfbox-2.0.24.jar.sha1 @@ -0,0 +1 @@ +cb562ee5f43e29415af4477e62fbe668ef88d18b \ No newline at end of file