Skip to content

Commit 449f958

Browse files
authored
Build/polaris-core: Remove outdated constraints (#2818)
The `:polaris-core` build scripts contains (soft) version-constraints for some dependencies with a vague reason "Vulnerability detected in ..." (concrete CVE/reason not mentioned) referencing specific dependency versions. The mentioned versions are all quite outdated, some are even not transitively referenced. Hence, removing those constraings, as those seem no longer relevant. Effective dependency versions can be inspected via `./gradlew :polaris-core:dependencies --configuration runtimeClasspath`.
1 parent e7b73b7 commit 449f958

File tree

1 file changed

+0
-29
lines changed

1 file changed

+0
-29
lines changed

polaris-core/build.gradle.kts

Lines changed: 0 additions & 29 deletions
Original file line numberDiff line numberDiff line change
@@ -28,9 +28,6 @@ dependencies {
2828
implementation(platform(libs.iceberg.bom))
2929
implementation("org.apache.iceberg:iceberg-api")
3030
implementation("org.apache.iceberg:iceberg-core")
31-
constraints {
32-
implementation("io.airlift:aircompressor:2.0.2") { because("Vulnerability detected in 0.25") }
33-
}
3431

3532
implementation(platform(libs.jackson.bom))
3633
implementation("com.fasterxml.jackson.core:jackson-annotations")
@@ -48,24 +45,6 @@ dependencies {
4845
compileOnly(project(":polaris-immutables"))
4946
annotationProcessor(project(":polaris-immutables", configuration = "processor"))
5047

51-
constraints {
52-
implementation("org.xerial.snappy:snappy-java:1.1.10.8") {
53-
because("Vulnerability detected in 1.1.8.2")
54-
}
55-
implementation("org.codehaus.jettison:jettison:1.5.4") {
56-
because("Vulnerability detected in 1.1")
57-
}
58-
implementation("org.apache.commons:commons-configuration2:2.12.0") {
59-
because("Vulnerability detected in 2.8.0")
60-
}
61-
implementation("org.apache.commons:commons-compress:1.28.0") {
62-
because("Vulnerability detected in 1.21")
63-
}
64-
implementation("com.nimbusds:nimbus-jose-jwt:10.5") {
65-
because("Vulnerability detected in 9.8.1")
66-
}
67-
}
68-
6948
implementation(libs.swagger.annotations)
7049
implementation(libs.swagger.jaxrs)
7150
implementation(libs.jakarta.inject.api)
@@ -86,14 +65,6 @@ dependencies {
8665
implementation("com.azure:azure-storage-common")
8766
implementation("com.azure:azure-identity")
8867
implementation("com.azure:azure-storage-file-datalake")
89-
constraints {
90-
implementation("io.netty:netty-codec-http2:4.2.6.Final") {
91-
because("Vulnerability detected in 4.1.72")
92-
}
93-
implementation("io.projectreactor.netty:reactor-netty-http:1.2.11") {
94-
because("Vulnerability detected in 1.0.45")
95-
}
96-
}
9768

9869
implementation("org.apache.iceberg:iceberg-gcp")
9970
implementation(platform(libs.google.cloud.storage.bom))

0 commit comments

Comments
 (0)