Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/build-mariadb.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ jobs:

services:
mariadb:
image: mariadb:11.5.2
image: mariadb:11.8.5
ports:
- 3306:3306
env:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/build-mysql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ jobs:

services:
mysql:
image: mysql:9.1
image: mysql:9.5
ports:
- 3306:3306
env:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/build-postgresql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ jobs:

services:
postgresql:
image: postgres:17.4
image: postgres:17.7
ports:
- 5432:5432
env:
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/liquibase-only-postgresql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ jobs:

services:
postgresql:
image: postgres:17.4
image: postgres:17.7
ports:
- 5432:5432
env:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ jobs:

services:
postgresql:
image: postgres:17.4
image: postgres:17.7
ports:
- 5432:5432
env:
Expand Down
28 changes: 14 additions & 14 deletions build.gradle
Original file line number Diff line number Diff line change
Expand Up @@ -95,28 +95,28 @@ buildscript {

plugins {
id 'me.qoomon.git-versioning' version '6.4.4'
id "org.barfuin.gradle.taskinfo" version "2.2.0"
id "org.barfuin.gradle.taskinfo" version "2.2.1"
id 'com.adarshr.test-logger' version '4.0.0'
id 'com.diffplug.spotless' version '6.25.0' apply false
id 'org.nosphere.apache.rat' version '0.8.1' apply false
id 'com.github.hierynomus.license' version '0.16.1' apply false
id 'com.github.jk1.dependency-license-report' version '2.9' apply false
id 'org.zeroturnaround.gradle.jrebel' version '1.2.0' apply false
id 'org.springframework.boot' version '3.5.6' apply false
id 'net.ltgt.errorprone' version '4.1.0' apply false
id 'io.swagger.core.v3.swagger-gradle-plugin' version '2.2.23' apply false
id 'com.gorylenko.gradle-git-properties' version '2.4.2' apply false
id 'org.zeroturnaround.gradle.jrebel' version '1.2.2' apply false
id 'org.springframework.boot' version '3.5.9' apply false
id 'net.ltgt.errorprone' version '4.3.0' apply false
id 'io.swagger.core.v3.swagger-gradle-plugin' version '2.2.41' apply false
id 'com.gorylenko.gradle-git-properties' version '2.5.4' apply false
id 'org.asciidoctor.jvm.convert' version '4.0.5' apply false
id 'org.asciidoctor.jvm.pdf' version '4.0.5' apply false
id 'com.google.cloud.tools.jib' version '3.4.5' apply false
id 'org.sonarqube' version '6.0.1.5171'
id 'com.github.andygoossens.modernizer' version '1.10.0' apply false
id 'com.github.spotbugs' version '6.0.26' apply false
id 'se.thinkcode.cucumber-runner' version '0.0.11' apply false
id 'com.google.cloud.tools.jib' version '3.5.2' apply false
id 'org.sonarqube' version '6.3.1.5724'
id 'com.github.andygoossens.modernizer' version '1.12.0' apply false
id 'com.github.spotbugs' version '6.4.8' apply false
id 'se.thinkcode.cucumber-runner' version '0.0.12' apply false
id "com.github.davidmc24.gradle.plugin.avro-base" version "1.9.1" apply false
id 'org.openapi.generator' version '7.8.0' apply false
id 'com.gradleup.shadow' version '8.3.5' apply false
id 'me.champeau.jmh' version '0.7.1' apply false
id 'org.openapi.generator' version '7.18.0' apply false
id 'com.gradleup.shadow' version '8.3.9' apply false
id 'me.champeau.jmh' version '0.7.3' apply false
}

apply from: "${rootDir}/buildSrc/src/main/groovy/org.apache.fineract.release.gradle"
Expand Down
2 changes: 1 addition & 1 deletion buildSrc/build.gradle
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ configurations.all {
resolutionStrategy {
dependencySubstitution {
// Substitution is to resolve CVE-2025-12183
substitute module('org.lz4:lz4-java') using module('at.yawk.lz4:lz4-java:1.10.1')
substitute module('org.lz4:lz4-java') using module('at.yawk.lz4:lz4-java:1.10.2')
}
}
}
Expand Down
174 changes: 87 additions & 87 deletions buildSrc/src/main/groovy/org.apache.fineract.dependencies.gradle
Original file line number Diff line number Diff line change
Expand Up @@ -24,56 +24,56 @@ dependencyManagement {
imports {
mavenBom 'com.squareup.okhttp3:okhttp-bom:4.12.0'
mavenBom 'org.slf4j:slf4j-bom:2.0.17'
mavenBom 'io.micrometer:micrometer-bom:1.13.6'
mavenBom 'org.springframework.boot:spring-boot-dependencies:3.5.6'
mavenBom 'io.awspring.cloud:spring-cloud-aws-dependencies:3.2.1'
mavenBom 'io.opentelemetry:opentelemetry-bom:1.44.1'
mavenBom 'org.jetbrains.kotlin:kotlin-bom:2.0.21'
mavenBom 'org.junit:junit-bom:5.11.3'
mavenBom 'com.fasterxml.jackson:jackson-bom:2.19.2'
mavenBom 'io.cucumber:cucumber-bom:7.20.1'
mavenBom 'org.mockito:mockito-bom:5.14.2'
mavenBom 'software.amazon.awssdk:bom:2.29.9'
mavenBom 'io.github.resilience4j:resilience4j-bom:2.2.0'
mavenBom 'org.testcontainers:testcontainers-bom:1.20.4'
mavenBom 'org.glassfish.jersey:jersey-bom:3.1.10'
mavenBom 'io.micrometer:micrometer-bom:1.16.1'
mavenBom 'org.springframework.boot:spring-boot-dependencies:3.5.9'
mavenBom 'io.awspring.cloud:spring-cloud-aws-dependencies:3.4.2'
mavenBom 'io.opentelemetry:opentelemetry-bom:1.57.0'
mavenBom 'org.jetbrains.kotlin:kotlin-bom:2.3.0'
mavenBom 'org.junit:junit-bom:5.14.1'
mavenBom 'com.fasterxml.jackson:jackson-bom:2.20.1'
mavenBom 'io.cucumber:cucumber-bom:7.33.0'
mavenBom 'org.mockito:mockito-bom:5.21.0'
mavenBom 'software.amazon.awssdk:bom:2.41.1'
mavenBom 'io.github.resilience4j:resilience4j-bom:2.3.0'
mavenBom 'org.testcontainers:testcontainers-bom:1.21.4'
mavenBom 'org.glassfish.jersey:jersey-bom:3.1.11'
}

dependencies {
// We use fixed versions, instead of inheriting them from the Spring BOM, to be able to be on more recent ones.
// We do not use :+ to get the latest available version available on Maven Central, as that could suddenly break things.
// We use the Renovate Bot to automatically propose Pull Requests (PRs) when upgrades for all of these versions are available.

dependency 'ch.qos.logback:logback-core:1.5.19'
dependency 'ch.qos.logback:logback-classic:1.5.19'
dependency 'ch.qos.logback:logback-core:1.5.23'
dependency 'ch.qos.logback:logback-classic:1.5.23'
dependency 'ch.qos.logback.contrib:logback-json-classic:0.1.5'
dependency 'ch.qos.logback.contrib:logback-jackson:0.1.5'
dependency 'org.codehaus.janino:janino:3.1.12'

dependency 'org.eclipse.persistence:org.eclipse.persistence.jpa:4.0.2'
dependency 'com.google.guava:guava:33.1.0-jre'
dependency 'com.google.code.gson:gson:2.11.0'
dependency 'com.google.googlejavaformat:google-java-format:1.24.0'
dependency 'org.apache.commons:commons-collections4:4.4'
dependency 'com.google.code.gson:gson:2.13.2'
dependency 'com.google.googlejavaformat:google-java-format:1.33.0'
dependency 'org.apache.commons:commons-collections4:4.5.0'
dependency 'org.apache.commons:commons-compress:1.28.0'
dependency ('software.amazon.msk:aws-msk-iam-auth:2.2.0') {
dependency ('software.amazon.msk:aws-msk-iam-auth:2.3.5') {
exclude 'commons-logging:commons-logging:'
}
dependency ('org.apache.commons:commons-email:1.6.0') {
exclude 'com.sun.mail:javax.mail'
exclude 'javax.activation:activation'
}
dependency 'commons-io:commons-io:2.18.0'
dependency 'commons-io:commons-io:2.21.0'
dependency 'com.github.librepdf:openpdf:3.0.0'
dependency ('org.mnode.ical4j:ical4j:3.2.19') {
exclude 'com.sun.mail:javax.mail'
exclude 'org.codehaus.groovy:groovy'
}
dependency 'org.apache.commons:commons-csv:1.12.0'
dependency 'org.quartz-scheduler:quartz:2.5.0'
dependency 'org.ehcache:ehcache:3.10.8'
dependency 'org.apache.commons:commons-csv:1.14.1'
dependency 'org.quartz-scheduler:quartz:2.5.2'
dependency 'org.ehcache:ehcache:3.11.1'
dependency 'com.github.spullara.mustache.java:compiler:0.9.14'
dependency 'com.jayway.jsonpath:json-path:2.9.0'
dependency 'com.jayway.jsonpath:json-path:2.10.0'
dependency ('org.apache.tika:tika-core:3.2.3') {
exclude 'commons-logging:commons-logging'
}
Expand Down Expand Up @@ -121,57 +121,57 @@ dependencyManagement {
dependency 'jakarta.jms:jakarta.jms-api:3.1.0'
dependency 'jakarta.ws.rs:jakarta.ws.rs-api:3.1.0'
dependency 'org.glassfish.jaxb:jaxb-runtime:2.3.6' // Swagger needs exactly this version
dependency 'joda-time:joda-time:2.13.1'
dependency 'joda-time:joda-time:2.14.0'

dependency 'io.github.classgraph:classgraph:4.8.179'
dependency 'org.awaitility:awaitility:4.2.2'
dependency 'com.github.spotbugs:spotbugs-annotations:4.8.6'
dependency 'io.github.classgraph:classgraph:4.8.184'
dependency 'org.awaitility:awaitility:4.3.0'
dependency 'com.github.spotbugs:spotbugs-annotations:4.9.8'
dependency 'javax.cache:cache-api:1.1.1'
dependency 'org.mock-server:mockserver-junit-jupiter:5.15.0'
dependency 'org.webjars:webjars-locator-core:0.59'
dependency 'com.icegreen:greenmail-junit5:2.0.1'

// fineract client dependencies
dependency "com.squareup.retrofit2:retrofit:2.11.0"
dependency "com.squareup.retrofit2:retrofit-mock:2.11.0"
dependency "com.squareup.retrofit2:adapter-java8:2.11.0"
dependency "com.squareup.retrofit2:adapter-rxjava2:2.11.0"
dependency "com.squareup.retrofit2:adapter-rxjava3:2.11.0"
dependency "com.squareup.retrofit2:adapter-guava:2.11.0"
dependency "com.squareup.retrofit2:converter-wire:2.11.0"
dependency "com.squareup.retrofit2:converter-jackson:2.11.0"
dependency "com.squareup.retrofit2:converter-simplexml:2.11.0"
dependency "com.squareup.retrofit2:converter-jaxb:2.11.0"
dependency "com.squareup.retrofit2:converter-java8:2.11.0"
dependency "com.squareup.retrofit2:converter-scalars:2.11.0"
dependency "com.squareup.retrofit2:converter-gson:2.11.0"
dependency "com.squareup.retrofit2:converter-protobuf:2.11.0"
dependency "com.squareup.retrofit2:retrofit:2.12.0"
dependency "com.squareup.retrofit2:retrofit-mock:2.12.0"
dependency "com.squareup.retrofit2:adapter-java8:2.12.0"
dependency "com.squareup.retrofit2:adapter-rxjava2:2.12.0"
dependency "com.squareup.retrofit2:adapter-rxjava3:2.12.0"
dependency "com.squareup.retrofit2:adapter-guava:2.12.0"
dependency "com.squareup.retrofit2:converter-wire:2.12.0"
dependency "com.squareup.retrofit2:converter-jackson:2.12.0"
dependency "com.squareup.retrofit2:converter-simplexml:2.12.0"
dependency "com.squareup.retrofit2:converter-jaxb:2.12.0"
dependency "com.squareup.retrofit2:converter-java8:2.12.0"
dependency "com.squareup.retrofit2:converter-scalars:2.12.0"
dependency "com.squareup.retrofit2:converter-gson:2.12.0"
dependency "com.squareup.retrofit2:converter-protobuf:2.12.0"
dependency 'io.reactivex.rxjava2:rxjava:2.2.21'
dependency "io.gsonfire:gson-fire:1.9.0"
dependency "com.google.code.findbugs:jsr305:3.0.2"
dependency "commons-codec:commons-codec:1.17.1"
dependency "org.projectlombok:lombok:1.18.36"
dependency "commons-codec:commons-codec:1.20.0"
dependency "org.projectlombok:lombok:1.18.42"

dependency 'org.bouncycastle:bcpkix-jdk18on:1.81'
dependency 'org.bouncycastle:bcprov-jdk18on:1.81'
dependency 'org.bouncycastle:bcutil-jdk18on:1.81'
dependency 'org.bouncycastle:bcpg-jdk18on:1.81'
dependency 'org.bouncycastle:bcpkix-jdk18on:1.83'
dependency 'org.bouncycastle:bcprov-jdk18on:1.83'
dependency 'org.bouncycastle:bcutil-jdk18on:1.83'
dependency 'org.bouncycastle:bcpg-jdk18on:1.83'

dependency 'org.eclipse.jgit:org.eclipse.jgit:7.2.0.202503040940-r'
dependency 'org.eclipse.jgit:org.eclipse.jgit.gpg.bc:7.2.0.202503040940-r'
dependency 'org.eclipse.jgit:org.eclipse.jgit.ssh.apache:7.2.0.202503040940-r'
dependency 'org.eclipse.jgit:org.eclipse.jgit:7.5.0.202512021534-r'
dependency 'org.eclipse.jgit:org.eclipse.jgit.gpg.bc:7.5.0.202512021534-r'
dependency 'org.eclipse.jgit:org.eclipse.jgit.ssh.apache:7.5.0.202512021534-r'

dependency ('com.tmatesoft.svnkit:svnkit:1.10.12')
dependency ('com.tmatesoft.svnkit:svnkit:1.10.13')
dependency 'com.vdurmont:semver4j:3.1.0'
dependency 'org.beryx:text-io:3.4.1'

dependency ('org.springdoc:springdoc-openapi-starter-webmvc-ui:2.6.0') {
dependency ('org.springdoc:springdoc-openapi-starter-webmvc-ui:2.8.15') {
exclude 'io.swagger.core.v3:swagger-core'
}

dependency 'com.google.cloud.sql:mysql-socket-factory-connector-j-8:1.23.1'
dependency 'com.google.cloud.sql:mysql-socket-factory-connector-j-8:1.27.1'

dependency ('org.apache.activemq:activemq-client:6.1.6') {
dependency ('org.apache.activemq:activemq-client:6.2.0') {
exclude 'javax.annotation:javax.annotation-api'
}

Expand All @@ -184,100 +184,100 @@ dependencyManagement {
}

dependency 'jakarta.annotation:jakarta.annotation-api:3.0.0'
dependency 'jakarta.activation:jakarta.activation-api:2.1.3'
dependency 'jakarta.activation:jakarta.activation-api:2.1.4'
dependency ('com.sun.mail:jakarta.mail:2.0.2') {
// Spring needs this version
exclude 'com.sun.activation:jakarta.activation'
}
dependency ('jakarta.xml.bind:jakarta.xml.bind-api:4.0.2') {
dependency ('jakarta.xml.bind:jakarta.xml.bind-api:4.0.4') {
exclude 'jakarta.activation:jakarta.activation-api'
}
dependency 'jakarta.validation:jakarta.validation-api:3.1.1'
dependency 'org.hibernate.validator:hibernate-validator:9.0.1.Final'
dependency 'org.hibernate.validator:hibernate-validator:9.1.0.Final'

dependency ('org.liquibase:liquibase-core:4.33.0') {
exclude 'javax.xml.bind:jaxb-api'
}
dependency 'org.liquibase.ext:liquibase-postgresql:4.33.0'

dependency ('org.dom4j:dom4j:2.1.4') {
dependency ('org.dom4j:dom4j:2.2.0') {
exclude 'relaxngDatatype:relaxngDatatype' // already in com.sun.xml.bind:jaxb-osgi:2.3.0.1
// FINERACT-940 && FINERACT-966 https://github.com/spotbugs/spotbugs/issues/1128
exclude 'xpp3:xpp3'
exclude 'pull-parser:pull-parser'
}

dependency 'org.owasp.esapi:esapi:2.7.0.0'
dependency 'org.awaitility:awaitility:4.2.2'
dependency 'org.awaitility:awaitility:4.3.0'

dependencySet(group: 'org.apache.poi', version: '5.4.1') {
dependencySet(group: 'org.apache.poi', version: '5.5.1') {
entry 'poi'
entry 'poi-ooxml'
entry 'poi-ooxml-schemas'
}

dependencySet(group: 'io.rest-assured', version: '5.5.1') {
dependencySet(group: 'io.rest-assured', version: '5.5.6') {
entry 'rest-assured'
entry 'json-path'
entry 'xml-path'
}
dependency 'org.apache.groovy:groovy-xml:5.0.2'
dependency 'org.apache.groovy:groovy-json:5.0.2'
dependency 'org.apache.groovy:groovy-xml:5.0.3'
dependency 'org.apache.groovy:groovy-json:5.0.3'

dependency 'org.mapstruct:mapstruct:1.6.3'
dependency 'org.mapstruct:mapstruct-processor:1.6.3'

dependency "org.apache.avro:avro:1.12.0"
dependency "org.apache.avro:avro:1.12.1"

dependency ('org.mariadb.jdbc:mariadb-java-client:3.5.2') {
dependency ('org.mariadb.jdbc:mariadb-java-client:3.5.7') {
exclude 'org.slf4j:jcl-over-slf4j'
exclude 'org.slf4j:slf4j-api'
}
dependency 'org.postgresql:postgresql:42.7.8'

dependency 'com.mysql:mysql-connector-j:9.2.0'
dependency 'com.mysql:mysql-connector-j:9.5.0'

dependency 'org.assertj:assertj-core:3.26.3'
dependency 'org.assertj:assertj-core:3.27.6'

dependency 'org.apache.commons:commons-math3:3.6.1'
dependency 'commons-beanutils:commons-beanutils:1.11.0'

dependency 'org.mockito:mockito-inline:5.2.0'

dependency 'org.wiremock:wiremock-standalone:3.13.0'
dependency 'org.apache.sshd:sshd-common:2.15.0'
dependency 'org.apache.sshd:sshd-core:2.15.0'
dependency 'org.wiremock:wiremock-standalone:3.13.2'
dependency 'org.apache.sshd:sshd-common:2.16.0'
dependency 'org.apache.sshd:sshd-core:2.16.0'

dependency 'io.cucumber:cucumber-java:7.20.1'
dependency 'io.cucumber:cucumber-java8:7.20.1'
dependency 'io.cucumber:cucumber-junit-platform-engine:7.20.1'
dependency 'io.cucumber:cucumber-spring:7.20.1'
dependency 'io.cucumber:cucumber-java:7.33.0'
dependency 'io.cucumber:cucumber-java8:7.33.0'
dependency 'io.cucumber:cucumber-junit-platform-engine:7.33.0'
dependency 'io.cucumber:cucumber-spring:7.33.0'

dependency 'org.reflections:reflections:0.10.2'

dependency 'org.openjdk.jmh:jmh-core:1.37'
dependency 'org.openjdk.jmh:jmh-generator-annprocess:1.37'

dependency 'org.springframework.restdocs:spring-restdocs-asciidoctor:3.0.3'
dependency 'org.springframework.restdocs:spring-restdocs-mockmvc:3.0.3'
dependency 'org.springframework.restdocs:spring-restdocs-webtestclient:3.0.3'
dependency 'org.springframework.restdocs:spring-restdocs-restassured:3.0.3'
dependency 'org.springframework.restdocs:spring-restdocs-asciidoctor:3.0.5'
dependency 'org.springframework.restdocs:spring-restdocs-mockmvc:3.0.5'
dependency 'org.springframework.restdocs:spring-restdocs-webtestclient:3.0.5'
dependency 'org.springframework.restdocs:spring-restdocs-restassured:3.0.5'

dependency 'com.lmax:disruptor:3.4.4'

dependency 'com.ibm.icu:icu4j:76.1'
dependency 'org.yakworks:spring-icu4j:0.4.2'
dependency 'org.apache.commons:commons-lang3:3.18.0'
dependency 'com.nimbusds:nimbus-jose-jwt:10.0.2'
dependency 'org.yakworks:spring-icu4j:0.5.2'
dependency 'org.apache.commons:commons-lang3:3.20.0'
dependency 'com.nimbusds:nimbus-jose-jwt:10.6'
// Force Spring Framework version: CVE-2025-41249
dependency 'org.springframework:spring-core:6.2.11'
dependency 'org.springframework:spring-core:6.2.15'
// Force Spring Framework version: CVE-2025-41248
dependency 'org.springframework.security:spring-security-core:6.5.4'
dependency 'org.springframework.security:spring-security-core:6.5.7'
// Force netty-codec version: CVE-2025-67735
dependency 'io.netty:netty-codec:4.1.129.Final'
dependency 'io.netty:netty-codec:4.2.9.Final'
// Force netty-codec version: CVE-2025-58056
dependency 'io.netty:netty-codec-http:4.1.129.Final'
dependency 'io.netty:netty-codec-http:4.2.9.Final'
// Force lz4-java version: CVE-2025-12183
dependency 'at.yawk.lz4:lz4-java:1.10.1'
dependency 'at.yawk.lz4:lz4-java:1.10.2'
}
}
Loading