diff --git a/pom.xml b/pom.xml index 5b001f2d3f610..9d5059329645d 100644 --- a/pom.xml +++ b/pom.xml @@ -291,7 +291,7 @@ flexible messaging model and an intuitive client API. 0.1.4 1.3 0.4 - 8.0.1 + 8.1.2 0.9.15 1.6.1 6.4.0 @@ -878,6 +878,24 @@ flexible messaging model and an intuitive client API. ${caffeine.version} + + org.bouncycastle + bcpkix-jdk15on + ${bouncycastle.version} + + + + com.cronutils + cron-utils + ${cron-utils.version} + + + org.glassfish + javax.el + + + + com.yahoo.athenz athenz-zts-java-client-core diff --git a/src/owasp-dependency-check-false-positives.xml b/src/owasp-dependency-check-false-positives.xml index 21a3679c0d8f7..345be8f4d2c06 100644 --- a/src/owasp-dependency-check-false-positives.xml +++ b/src/owasp-dependency-check-false-positives.xml @@ -182,6 +182,16 @@ CVE-2021-4277 + + It treat pulsar-io-kafka-connect-adaptor as a lib of Kafka, CVE-2021-25194 is a false positive. + CVE-2023-25194 + + + + It treat pulsar-io-kafka-connect-adaptor as a lib of Kafka, CVE-2021-34917 is a false positive. + CVE-2022-34917 + + yaml_project is not used at all. Any CVEs reported for yaml_project are false positives. cpe:/a:yaml_project:yaml