From cedd3a7dfb2eebbe21ebebf32a408a5fa8e31bdc Mon Sep 17 00:00:00 2001 From: "Mark S. Lewis" Date: Mon, 21 Aug 2023 10:16:57 +0100 Subject: [PATCH] Update opentelemetry-grpc-1.6 dependency (#289) Also update dependency-check suppressions to remove false positives. Signed-off-by: Mark S. Lewis --- dependency-suppressions.xml | 14 ++++++++++++++ pom.xml | 4 ++-- 2 files changed, 16 insertions(+), 2 deletions(-) diff --git a/dependency-suppressions.xml b/dependency-suppressions.xml index fbf9371b..790ae92d 100644 --- a/dependency-suppressions.xml +++ b/dependency-suppressions.xml @@ -1,3 +1,17 @@ + + + ^pkg:maven/io\.opentelemetry\.instrumentation/opentelemetry\-grpc\-1\.6@.*$ + CVE-2023-33953 + + + + ^pkg:maven/io\.opentelemetry\.instrumentation/opentelemetry\-grpc\-1\.6@.*$ + CVE-2023-32732 + diff --git a/pom.xml b/pom.xml index b9592c78..f967ded3 100644 --- a/pom.xml +++ b/pom.xml @@ -28,7 +28,7 @@ http://github.com/hyperledger/fabric-sdk-java - 1.57.1 + 1.57.2 3.22.5 1.76 4.5.14 @@ -222,7 +222,7 @@ io.opentelemetry.instrumentation opentelemetry-grpc-1.6 - 1.28.0-alpha + 1.29.0-alpha io.opentelemetry.proto