Pārlūkot izejas kodu

fix 修复 依赖漏洞 限制部分依赖版本

疯狂的狮子Li 8 mēneši atpakaļ
vecāks
revīzija
31569646b0

+ 22 - 0
pom.xml

@@ -319,6 +319,28 @@
                 <version>${ip2region.version}</version>
             </dependency>
 
+            <dependency>
+                <groupId>io.undertow</groupId>
+                <artifactId>undertow-core</artifactId>
+                <version>${undertow.version}</version>
+            </dependency>
+            <dependency>
+                <groupId>io.undertow</groupId>
+                <artifactId>undertow-servlet</artifactId>
+                <version>${undertow.version}</version>
+            </dependency>
+            <dependency>
+                <groupId>io.undertow</groupId>
+                <artifactId>undertow-websockets-jsr</artifactId>
+                <version>${undertow.version}</version>
+            </dependency>
+
+            <dependency>
+                <artifactId>commons-compress</artifactId>
+                <groupId>org.apache.commons</groupId>
+                <version>1.26.2</version>
+            </dependency>
+
             <dependency>
                 <groupId>com.alibaba</groupId>
                 <artifactId>fastjson</artifactId>

+ 0 - 3
ruoyi-common/ruoyi-common-web/pom.xml

@@ -46,17 +46,14 @@
         <dependency>
             <groupId>io.undertow</groupId>
             <artifactId>undertow-core</artifactId>
-            <version>${undertow.version}</version>
         </dependency>
         <dependency>
             <groupId>io.undertow</groupId>
             <artifactId>undertow-servlet</artifactId>
-            <version>${undertow.version}</version>
         </dependency>
         <dependency>
             <groupId>io.undertow</groupId>
             <artifactId>undertow-websockets-jsr</artifactId>
-            <version>${undertow.version}</version>
         </dependency>
 
         <dependency>

+ 1 - 1
ruoyi-modules/ruoyi-workflow/pom.xml

@@ -57,7 +57,7 @@
         <dependency>
             <groupId>org.apache.xmlgraphics</groupId>
             <artifactId>batik-all</artifactId>
-            <version>1.10</version>
+            <version>1.17</version>
             <exclusions>
                 <exclusion>
                     <groupId>xalan</groupId>