diff --git a/gradle/owasp-suppression.xml b/gradle/owasp-suppression.xml index 42beb909..0fcb7658 100644 --- a/gradle/owasp-suppression.xml +++ b/gradle/owasp-suppression.xml @@ -1,23 +1,12 @@ - - - ^pkg:maven/io\.netty/netty*@*.*$ - CVE-2023-4586 - - + - ^pkg:maven/com\.azure/azure\-identity@1\.10\.[2-9]$ + ^pkg:maven/com\.azure/azure\-identity@1\.11\.[1-9]$ CVE-2023-36415 @@ -37,21 +26,21 @@ ]]> CVE-2020-8908 - + ^pkg:maven/com\.azure/azure*@*.*$ CVE-2023-36052 - + ^pkg:maven/io\.grpc/grpc\-.*$ CVE-2023-44487 - + diff --git a/gradle/versions.gradle b/gradle/versions.gradle index 98bc9f7e..3f59c6b9 100644 --- a/gradle/versions.gradle +++ b/gradle/versions.gradle @@ -136,11 +136,11 @@ dependencyManagement { } //overriding Azure libraries dependencies as we don't update signers library anymore - dependencySet(group: 'com.azure', version: '4.7.1') { + dependencySet(group: 'com.azure', version: '4.7.3') { entry 'azure-security-keyvault-secrets' entry 'azure-security-keyvault-keys' } - dependency 'com.azure:azure-identity:1.10.4' + dependency 'com.azure:azure-identity:1.11.1' /* io.projectreactor.netty:reactor-netty-http:1.0.38 -> 1.0.39 // CVE-2023-34062