diff --git a/build.gradle b/build.gradle index 52d835983e..b62d153542 100644 --- a/build.gradle +++ b/build.gradle @@ -331,7 +331,7 @@ allprojects { force "org.bouncycastle:bcprov-jdk18on:${bouncycastleVersion}" // force consistency in docker and connectors and saml force "org.bouncycastle:bcpkix-jdk18on:${bouncycastleVersion}" - // docker dependency: force to mitigate CVEs in 4.1.46 + // docker dependency: force to mitigate CVEs force "io.netty:netty-resolver:${nettyVersion}" force "io.netty:netty-resolver-dns:${nettyVersion}" force "io.netty:netty-handler:${nettyVersion}" diff --git a/dependencyCheckSuppression.xml b/dependencyCheckSuppression.xml index 423ec9f23d..199d8ab5db 100644 --- a/dependencyCheckSuppression.xml +++ b/dependencyCheckSuppression.xml @@ -248,4 +248,16 @@ ^pkg:maven/com\.google\.code\.gson/gson@.*$ CVE-2025-53864 + + + + + ^pkg:maven/org\.mozilla/rhino@.*$ + CVE-2025-66453 + diff --git a/gradle.properties b/gradle.properties index af581ad27b..f6bea1b219 100644 --- a/gradle.properties +++ b/gradle.properties @@ -44,7 +44,7 @@ buildFromSource=true # The default version for LabKey artifacts that are built or that we depend on. # override in an individual module's gradle.properties file as necessary -labkeyVersion=25.7.18 +labkeyVersion=25.7.19 labkeyClientApiVersion=6.3.0 # Version numbers for the various binary artifacts that are included when @@ -135,7 +135,7 @@ commonsLangVersion=2.6 commonsLoggingVersion=1.3.5 commonsMath3Version=3.6.1 commonsPoolVersion=1.6 -commonsTextVersion=1.13.1 +commonsTextVersion=1.15.0 commonsValidatorVersion=1.9.0 commonsVfs2Version=2.10.0 @@ -238,7 +238,7 @@ jxlVersion=2.6.3 kaptchaVersion=2.3 -log4j2Version=2.24.3 +log4j2Version=2.25.3 lombokVersion=1.18.38 @@ -247,7 +247,7 @@ luceneVersion=9.12.2 mssqlJdbcVersion=13.2.1.jre11 # force for docker -nettyVersion=4.2.5.Final +nettyVersion=4.2.9.Final objenesisVersion=1.0