Bump Jetty to 9.4.17.v20190418 due to CVE-2019-10247

+ remove older version of package-info-maven-plugin
This commit is contained in:
catbref 2019-04-30 09:00:30 +01:00
parent 882d910631
commit 747f5e41cf
5 changed files with 10 additions and 30 deletions

View File

@ -1,9 +0,0 @@
<?xml version="1.0" encoding="UTF-8"?>
<project xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd" xmlns="http://maven.apache.org/POM/4.0.0"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<modelVersion>4.0.0</modelVersion>
<groupId>com.github.bohnman</groupId>
<artifactId>package-info-maven-plugin</artifactId>
<version>1.0.2-m2e</version>
<description>POM was created from install:install-file</description>
</project>

View File

@ -1,12 +0,0 @@
<?xml version="1.0" encoding="UTF-8"?>
<metadata>
<groupId>com.github.bohnman</groupId>
<artifactId>package-info-maven-plugin</artifactId>
<versioning>
<release>1.0.2-m2e</release>
<versions>
<version>1.0.2-m2e</version>
</versions>
<lastUpdated>20190326110305</lastUpdated>
</versioning>
</metadata>

View File

@ -11,14 +11,14 @@
<dagger.version>1.2.2</dagger.version> <dagger.version>1.2.2</dagger.version>
<hsqldb.version>r5970</hsqldb.version> <hsqldb.version>r5970</hsqldb.version>
<sqltool.version>2.4.1</sqltool.version> <sqltool.version>2.4.1</sqltool.version>
<jetty.version>9.4.12.v20180830</jetty.version> <jetty.version>9.4.17.v20190418</jetty.version>
<jersey.version>2.27</jersey.version> <jersey.version>2.27</jersey.version>
<log4j.version>2.11.0</log4j.version> <log4j.version>2.11.0</log4j.version>
<slf4j.version>1.7.12</slf4j.version> <slf4j.version>1.7.12</slf4j.version>
<swagger-api.version>2.0.6</swagger-api.version> <swagger-api.version>2.0.6</swagger-api.version>
<swagger-ui.version>3.19.0</swagger-ui.version> <swagger-ui.version>3.19.0</swagger-ui.version>
<felix-bundle-plugin.version>3.5.0</felix-bundle-plugin.version> <felix-bundle-plugin.version>3.5.0</felix-bundle-plugin.version>
<package-info-maven-plugin.version>1.0.2-m2e</package-info-maven-plugin.version> <package-info-maven-plugin.version>1.1.0</package-info-maven-plugin.version>
<build.timestamp>${maven.build.timestamp}</build.timestamp> <build.timestamp>${maven.build.timestamp}</build.timestamp>
</properties> </properties>
<build> <build>
@ -312,7 +312,7 @@
<dependency> <dependency>
<groupId>com.github.bohnman</groupId> <groupId>com.github.bohnman</groupId>
<artifactId>package-info-maven-plugin</artifactId> <artifactId>package-info-maven-plugin</artifactId>
<version>1.0.1</version> <version>${package-info-maven-plugin.version}</version>
</dependency> </dependency>
<dependency> <dependency>
<groupId>org.apache.felix</groupId> <groupId>org.apache.felix</groupId>

View File

@ -4,7 +4,9 @@ import io.swagger.v3.jaxrs2.integration.resources.OpenApiResource;
import org.eclipse.jetty.rewrite.handler.RedirectPatternRule; import org.eclipse.jetty.rewrite.handler.RedirectPatternRule;
import org.eclipse.jetty.rewrite.handler.RewriteHandler; import org.eclipse.jetty.rewrite.handler.RewriteHandler;
import org.eclipse.jetty.server.NCSARequestLog; import org.eclipse.jetty.server.CustomRequestLog;
import org.eclipse.jetty.server.RequestLog;
import org.eclipse.jetty.server.RequestLogWriter;
import org.eclipse.jetty.server.Server; import org.eclipse.jetty.server.Server;
import org.eclipse.jetty.server.handler.ErrorHandler; import org.eclipse.jetty.server.handler.ErrorHandler;
import org.eclipse.jetty.server.handler.InetAccessHandler; import org.eclipse.jetty.server.handler.InetAccessHandler;
@ -40,11 +42,10 @@ public class ApiService {
// Request logging // Request logging
if (Settings.getInstance().isApiLoggingEnabled()) { if (Settings.getInstance().isApiLoggingEnabled()) {
NCSARequestLog requestLog = new NCSARequestLog("API-requests.log"); RequestLogWriter logWriter = new RequestLogWriter("API-requests.log");
requestLog.setAppend(true); logWriter.setAppend(true);
requestLog.setExtended(false); logWriter.setTimeZone("UTC");
requestLog.setLogTimeZone("UTC"); RequestLog requestLog = new CustomRequestLog(logWriter, CustomRequestLog.EXTENDED_NCSA_FORMAT);
requestLog.setLogLatency(true);
server.setRequestLog(requestLog); server.setRequestLog(requestLog);
} }