From 7ded0968c1e699fdf84c3d106bfc27c9e7ae536f Mon Sep 17 00:00:00 2001 From: Nanne Baars Date: Mon, 20 Dec 2021 17:29:25 +0100 Subject: [PATCH] Ban log4j all together and update OWASP dep check Remove --- pom.xml | 48 ++++++++++++++++++++++++++++++++++++++---------- 1 file changed, 38 insertions(+), 10 deletions(-) diff --git a/pom.xml b/pom.xml index cbc888ee0..84fca14d0 100644 --- a/pom.xml +++ b/pom.xml @@ -133,6 +133,8 @@ 3.0.0-M5 17 3.0.14.RELEASE + 3.15.0 + 3.1.2 @@ -141,14 +143,15 @@ webgoat-server webwolf webgoat-integration-tests - docker + docker + - - org.springframework.boot - spring-boot-starter-validation - + + org.springframework.boot + spring-boot-starter-validation + org.projectlombok lombok @@ -187,7 +190,7 @@ org.apache.maven.plugins maven-checkstyle-plugin - 3.1.2 + ${checkstyle.version} UTF-8 true @@ -200,10 +203,11 @@ org.apache.maven.plugins maven-pmd-plugin - 3.14.0 + ${pmd.version} - 15 - 1 + ${maven.compiler.target} + 1 + ${maven.multiModuleProjectDirectory}/config/pmd/pmd-ruleset.xml @@ -219,6 +223,30 @@ + + org.apache.maven.plugins + maven-enforcer-plugin + 3.0.0 + + + Restrict-bad-log4j-versions + validate + + enforce + + + + + + org.apache.logging.log4j:log4j-core:(,2.15.0) + + + + true + + + + @@ -233,7 +261,7 @@ org.owasp dependency-check-maven - 6.1.3 + 6.5.1 7 true