diff --git a/owasp-suppressions.xml b/owasp-suppressions.xml index d2e529a..306a247 100644 --- a/owasp-suppressions.xml +++ b/owasp-suppressions.xml @@ -56,12 +56,4 @@ CVE-2018-11770 CVE-2018-17190 - - - ^pkg:maven/commons\-httpclient/commons\-httpclient@.*$ - CVE-2012-5783 - CVE-2020-13956 - diff --git a/view-creator-framework/build.gradle.kts b/view-creator-framework/build.gradle.kts index 18d9199..5d871e7 100644 --- a/view-creator-framework/build.gradle.kts +++ b/view-creator-framework/build.gradle.kts @@ -17,7 +17,7 @@ dependencies { api("org.apache.commons:commons-compress:1.26.0") { because("https://www.tenable.com/cve/CVE-2024-25710") } - implementation("org.apache.pinot:pinot-tools:0.12.1") { + implementation("org.apache.pinot:pinot-tools:1.0.0") { // All these third party libraries are not used in view creation workflow. // They bring in lot of vulnerabilities (snyk). so, excluding unused libs exclude("com.google.protobuf", "protobuf-java")