Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Third-party Dependency Upgrades for APIM 4.4.0 #3105

Closed
YasasRangika opened this issue Sep 10, 2024 · 11 comments
Closed

Third-party Dependency Upgrades for APIM 4.4.0 #3105

YasasRangika opened this issue Sep 10, 2024 · 11 comments

Comments

@YasasRangika
Copy link

Description

This issue is created to track the third-party dependency upgrades for the APIM 4.4.0 release. Each upgraded dependency will be mentioned in the comments.

Affected Component

APIM

Version

4.4.0

Related Issues

No response

Suggested Labels

No response

@YasasRangika
Copy link
Author

YasasRangika commented Sep 10, 2024

[STATUS UPDATE]

Provided a docker image of the APIM-4.4.0-m2 pack to the security team for the JFrog Analysis report.

@npamudika
Copy link

Refer #3014

@YasasRangika
Copy link
Author

[STATUS UPDATE]

Upgrade CXF version from 3.6.3 to 3.6.4:

wso2/carbon-apimgt#12556
wso2/product-apim#13530
wso2/carbon-deployment#401

@YasasRangika
Copy link
Author

[STATUS UPDATE]

Upgrade bcprov-jdk18on and bcpkix-jdk18on Bouncy Castle dependencies from 1.77.0.wso2v1 to 1.78.1.wso2v1. Also, upgrade the bc-fips version from 1.0.2.4 to 1.0.2.5.

carbon-multitenancy PR: wso2/carbon-multitenancy#270
wso2-synapse PR: wso2/wso2-synapse#2217
carbon-apimgt PR: wso2/carbon-apimgt#12567
carbon-kernel PR: wso2/carbon-kernel#4074
product-apim PR: wso2/product-apim#13532

@YasasRangika
Copy link
Author

[STATUS UPDATE]

Upgraded the Tomcat versions from 9.0.85.wso2v1 to 9.0.94.wso2v1 and tested the portals with the major REST APIs.

Orbit PR: wso2/orbit#1132
carbon-kernel PR: wso2/carbon-kernel#4075

@YasasRangika
Copy link
Author

[STATUS UPDATE]

Upgraded the swagger-parser version from 2.1.18 and 2.1.20 (both versions were packed from the 4.3.0 release) to version 2.1.22.

Orbit bundles: wso2/orbit#1133
carbon-mediation PR: wso2/carbon-mediation#1733
carbon-apimgt PR: wso2/carbon-apimgt#12586
product-apim PR: wso2/product-apim#13540

@YasasRangika
Copy link
Author

[STATUS UPDATE]

Upgraded the protobuf-java version from 3.21.12 to non-vulnerable 3.25.5. Tested basic flows and thoroughly tested the streaming APIs.

carbon-business-messaging PR: wso2/carbon-business-messaging#726
carbon-apimgt PR: wso2/carbon-apimgt#12642
product-apim PR: wso2/product-apim#13559

@YasasRangika
Copy link
Author

[STATUS UPDATE]

Upgraded the swagger-parser version from 2.1.20.wso2v1 to 2.1.20.wso2v2 to resolve packing vulnerable version 2.11.0 of commons.io.

Orbit bundles: wso2/orbit#1140
carbon-mediation PR: wso2/carbon-mediation#1734
carbon-apimgt PR: wso2/carbon-apimgt#12651

@YasasRangika
Copy link
Author

[STATUS UPDATE]

Upgraded the commons-text version from 1.6.0 to 1.10.0.

carbon-mediation PR: wso2/carbon-mediation#1735
carbon-kernel PR: wso2/carbon-kernel#4087

@YasasRangika
Copy link
Author

[STATUS UPDATE]

Upgraded the Jettison version from 1.3.4 to 1.5.4.

carbon-kernel PR: wso2/carbon-kernel#4089

@YasasRangika
Copy link
Author

[STATUS UPDATE]

Upgraded the graphQL version from 19.6 to 19.11.

Orbit PR: wso2/orbit#1143
carbon-apimgt PR: wso2/carbon-apimgt#12663

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants