Skip to content

Commit

Permalink
AAE-29930 Fix HQL injection by replacing the querydsl package with a …
Browse files Browse the repository at this point in the history
…patched version of a fork from OpenFeign (#1664)

* switch to patched version of the fork

* update to patched version
  • Loading branch information
matthiasHOnGithub authored Jan 16, 2025
1 parent 63e6a66 commit 74254f1
Show file tree
Hide file tree
Showing 11 changed files with 28 additions and 28 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@
<packaging>pom</packaging>
<name>Activiti Cloud :: Audit Dependencies BOM (Bill Of Materials)</name>
<properties>
<querydsl.version>5.1.0</querydsl.version>
<querydsl.version>5.6.1</querydsl.version>
</properties>
<dependencyManagement>
<dependencies>
Expand Down Expand Up @@ -92,19 +92,19 @@
<version>${project.version}</version>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-apt</artifactId>
<version>${querydsl.version}</version>
<scope>provided</scope>
<classifier>jakarta</classifier>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-core</artifactId>
<version>${querydsl.version}</version>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-jpa</artifactId>
<version>${querydsl.version}</version>
<classifier>jakarta</classifier>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -91,9 +91,9 @@
<scope>test</scope>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-apt</artifactId>
<version>5.1.0</version>
<version>5.6.1</version>
<scope>provided</scope>
<classifier>jakarta</classifier>
</dependency>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -79,9 +79,9 @@
<artifactId>hibernate-core</artifactId>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-apt</artifactId>
<version>5.1.0</version>
<version>5.6.1</version>
<scope>provided</scope>
<classifier>jakarta</classifier>
</dependency>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@
<artifactId>slf4j-api</artifactId>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-core</artifactId>
</dependency>
<dependency>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -95,7 +95,7 @@
<artifactId>slf4j-api</artifactId>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-core</artifactId>
</dependency>
<dependency>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -97,7 +97,7 @@
<artifactId>slf4j-api</artifactId>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-core</artifactId>
</dependency>
<dependency>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@
<artifactId>activiti-cloud-notifications-graphql-dependencies</artifactId>
<packaging>pom</packaging>
<properties>
<querydsl.version>5.1.0</querydsl.version>
<querydsl.version>5.6.1</querydsl.version>
</properties>
<dependencyManagement>
<dependencies>
Expand Down Expand Up @@ -66,19 +66,19 @@
<version>${project.version}</version>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-apt</artifactId>
<version>${querydsl.version}</version>
<scope>provided</scope>
<classifier>jakarta</classifier>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-core</artifactId>
<version>${querydsl.version}</version>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-jpa</artifactId>
<version>${querydsl.version}</version>
<classifier>jakarta</classifier>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@
<packaging>pom</packaging>
<name>Activiti Cloud :: Query Dependencies BOM (Bill Of Materials)</name>
<properties>
<querydsl.version>5.1.0</querydsl.version>
<querydsl.version>5.6.1</querydsl.version>
</properties>
<dependencyManagement>
<dependencies>
Expand Down Expand Up @@ -87,19 +87,19 @@
<version>${project.version}</version>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-apt</artifactId>
<version>${querydsl.version}</version>
<scope>provided</scope>
<classifier>jakarta</classifier>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-core</artifactId>
<version>${querydsl.version}</version>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-jpa</artifactId>
<version>${querydsl.version}</version>
<classifier>jakarta</classifier>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -68,18 +68,18 @@
<scope>test</scope>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-apt</artifactId>
<version>${querydsl.version}</version>
<scope>provided</scope>
<classifier>jakarta</classifier>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-core</artifactId>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-jpa</artifactId>
<classifier>jakarta</classifier>
<version>${querydsl.version}</version>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -23,18 +23,18 @@
<artifactId>spring-context</artifactId>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-apt</artifactId>
<version>${querydsl.version}</version>
<scope>provided</scope>
<classifier>jakarta</classifier>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-core</artifactId>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-jpa</artifactId>
<classifier>jakarta</classifier>
</dependency>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -117,18 +117,18 @@
<artifactId>jackson-annotations</artifactId>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-apt</artifactId>
<version>${querydsl.version}</version>
<scope>provided</scope>
<classifier>jakarta</classifier>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-core</artifactId>
</dependency>
<dependency>
<groupId>com.querydsl</groupId>
<groupId>io.github.openfeign.querydsl</groupId>
<artifactId>querydsl-jpa</artifactId>
<classifier>jakarta</classifier>
</dependency>
Expand Down

0 comments on commit 74254f1

Please sign in to comment.