From 3e4c39dfacc5f0e7bc0240d3a9cbda845d86c535 Mon Sep 17 00:00:00 2001 From: Adam Valenta Date: Thu, 24 Oct 2024 15:09:44 +0200 Subject: [PATCH] GH-16423 - fix hadoop jars after gcs upgrade [nocheck] (#16428) * downgrade google gcs * upgrade only protobuf --- h2o-persist-gcs/build.gradle | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/h2o-persist-gcs/build.gradle b/h2o-persist-gcs/build.gradle index 507ef11e51bf..d07448510c39 100644 --- a/h2o-persist-gcs/build.gradle +++ b/h2o-persist-gcs/build.gradle @@ -4,10 +4,18 @@ description = "H2O Persist GCS" dependencies { api project(":h2o-core") - api ('com.google.cloud:google-cloud-storage:2.43.2') + api ('com.google.cloud:google-cloud-storage:2.13.1') testImplementation project(":h2o-test-support") testRuntimeOnly project(":${defaultWebserverModule}") + + constraints { + api('com.google.protobuf:protobuf-java:3.25.5') { + because 'Fixes CVE-2024-7254' + because 'Fixes SNYK-JAVA-COMGOOGLEPROTOBUF-8055227' + because 'Fixes SNYK-JAVA-COMGOOGLEPROTOBUF-8055228' + } + } } apply from: "${rootDir}/gradle/dataCheck.gradle"