diff --git a/build.gradle b/build.gradle index cb287d77..eaeb4c89 100644 --- a/build.gradle +++ b/build.gradle @@ -25,7 +25,7 @@ buildscript { dependencies { // custom license-reporter used by com.github.jk1.dependency-license-report plugin classpath 'tech.pegasys.internal.license.reporter:license-reporter:1.0.1' - classpath 'org.owasp:dependency-check-gradle:8.4.0' + classpath 'org.owasp:dependency-check-gradle:8.4.2' } } diff --git a/gradle/owasp-suppression.xml b/gradle/owasp-suppression.xml index 43d872f5..ab9a1820 100644 --- a/gradle/owasp-suppression.xml +++ b/gradle/owasp-suppression.xml @@ -1,9 +1,21 @@ - + + + ^pkg:maven/io\.netty/netty*@*.*$ + CVE-2023-4586 + + ^pkg:maven/com\.azure/azure\-identity@1\.10\.[2-9]$ CVE-2023-36415 diff --git a/gradle/versions.gradle b/gradle/versions.gradle index 8ee62a10..14c7f867 100644 --- a/gradle/versions.gradle +++ b/gradle/versions.gradle @@ -112,7 +112,7 @@ dependencyManagement { entry 'protobuf-java' entry 'protobuf-java-util' } - dependencySet(group: 'io.grpc', version: '1.57.2') { + dependencySet(group: 'io.grpc', version: '1.59.0') { entry 'grpc-api' entry 'grpc-context' entry 'grpc-core'