Skip to content

Commit

Permalink
Update dependencies
Browse files Browse the repository at this point in the history
  • Loading branch information
michaelmior committed Feb 29, 2024
1 parent f8b1bab commit 0352f45
Showing 1 changed file with 12 additions and 12 deletions.
24 changes: 12 additions & 12 deletions project/Dependencies.scala
Original file line number Diff line number Diff line change
Expand Up @@ -11,29 +11,29 @@ object Dependencies {
lazy val ddSketch = "com.datadoghq" % "sketches-java" % "0.8.2"
lazy val fuzzySets = "io.github.dataunitylab" %% "fuzzy-sets" % "0.4.0"
lazy val hyperLogLog = "com.github.prasanthj" % "hyperloglog" % "1.1"
lazy val jsonSchemaValidator = "com.networknt" % "json-schema-validator" % "1.0.87"
lazy val jsonSchemaValidator = "com.networknt" % "json-schema-validator" % "1.3.3"
lazy val openLocationCode = "com.google.openlocationcode" % "openlocationcode" % "1.0.4"
lazy val scopt = "com.github.scopt" %% "scopt" % "4.1.0"
lazy val scalaCsv = "com.github.tototoshi" %% "scala-csv" % "1.3.10"
lazy val spark = "org.apache.spark" %% "spark-core" % "3.4.0"
lazy val sparkSql = "org.apache.spark" %% "spark-sql" % "3.4.0"
lazy val validator = "commons-validator" % "commons-validator" % "1.7"
lazy val spark = "org.apache.spark" %% "spark-core" % "3.5.1"
lazy val sparkSql = "org.apache.spark" %% "spark-sql" % "3.5.1"
lazy val validator = "commons-validator" % "commons-validator" % "1.8.0"

// Test
lazy val jazzer = "com.code-intelligence" % "jazzer" % "0.16.1"
lazy val scalactic = "org.scalactic" %% "scalactic" % "3.2.17"
lazy val scalaTest = "org.scalatest" %% "scalatest" % "3.2.17"
lazy val scalaTestPlus = "org.scalatestplus" %% "scalacheck-1-17" % "3.2.17.0"
lazy val jazzer = "com.code-intelligence" % "jazzer" % "0.22.1"
lazy val scalactic = "org.scalactic" %% "scalactic" % "3.2.18"
lazy val scalaTest = "org.scalatest" %% "scalatest" % "3.2.18"
lazy val scalaTestPlus = "org.scalatestplus" %% "scalacheck-1-17" % "3.2.18.0"
lazy val scalaCheck = "org.scalacheck" %% "scalacheck" % "1.17.0"


// Overrides
// XXX Bundled version is vulnerable to CVE-2018-10237
lazy val guava = "com.google.guava" % "guava" % "31.1-jre"
lazy val guava = "com.google.guava" % "guava" % "33.0.0-jre"
// XXX This is necessary for Spark version consistency
lazy val jacksonDatabind = "com.fasterxml.jackson.core" % "jackson-databind" % "2.14.3"
lazy val jacksonDatabind = "com.fasterxml.jackson.core" % "jackson-databind" % "2.15.2"
// XXX Version bundled with Spark is vulnerable to CVE-2022-3171
lazy val protobuf = "com.google.protobuf" % "protobuf-java" % "3.23.0"
lazy val protobuf = "com.google.protobuf" % "protobuf-java" % "3.25.3"
// XXX Bundled version is vulnerable to CVE-2023-34455
lazy val snappyJava = "org.xerial.snappy" % "snappy-java" % "1.1.10.1"
lazy val snappyJava = "org.xerial.snappy" % "snappy-java" % "1.1.10.5"
}

0 comments on commit 0352f45

Please sign in to comment.