[ANALYTICS-178] Update google api client to 1.30.10 Created: 22/Jul/20  Updated: 29/Jul/20  Resolved: 24/Jul/20

Status: Closed
Project: Analytics
Component/s: None
Affects Version/s: None
Fix Version/s: 1.2

Type: Bug Priority: Major
Reporter: Oanh Thai Hoang Assignee: Thuy To
Resolution: Fixed Votes: 0
Labels: None
Remaining Estimate: 0d
Time Spent: 1d 7h
Original Estimate: Not Specified

Attachments: PNG File Screen Shot 2020-07-22 at 09.20.01.png    
Template:
Acceptance criteria:
Empty
Task DoD:
[ ]* Doc/release notes changes? Comment present?
[ ]* Downstream builds green?
[ ]* Solution information and context easily available?
[ ]* Tests
[ ]* FixVersion filled and not yet released
[ ]  Architecture Decision Record (ADR)
Bug DoR:
[ ]* Steps to reproduce, expected, and actual results filled
[ ]* Affected version filled
Date of First Response:
Epic Link: Analytics UI dashboard
Sprint: Add-Ons 43
Story Points: 1

 Description   

The current google api bring a security issue, here is the log found by jenkins

[INFO] [jenkins-event-spy] Generated /var/lib/jenkins/workspace/addon_addon-tests_master@tmp/withMavena72e653a/maven-spy-20200722-010332-6376038716968969703672.log
[ERROR] Failed to execute goal org.owasp:dependency-check-maven:5.3.1:check (default-cli) on project magnolia-addon-test-author-webapp: 
[ERROR] 
[ERROR] One or more dependencies were identified with vulnerabilities: 
[ERROR] 
[ERROR] google-oauth-client-1.22.0.jar: CVE-2020-7692
[ERROR] magnolia-addon-webapp-6.2.1-SNAPSHOT.war: google-oauth-client-1.30.5.jar: CVE-2020-7692
[ERROR] 
[ERROR] See the dependency-check report for more details.
[ERROR] -> [Help 1]
[ERROR] 
[ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch.
[ERROR] Re-run Maven using the -X switch to enable full debug logging.
[ERROR] 
[ERROR] For more information about the errors and possible solutions, please read the following articles:
[ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/MojoFailureException

See it in analytics module



 Comments   
Comment by Thuy To [ 24/Jul/20 ]

Need to fix laterĀ https://jira.magnolia-cms.com/browse/ANALYTICS-179

Generated at Sun Feb 11 23:16:18 CET 2024 using Jira 9.4.2#940002-sha1:46d1a51de284217efdcb32434eab47a99af2938b.