diff --git a/backend/build.gradle b/backend/build.gradle index d7e960e7..67bf9f52 100644 --- a/backend/build.gradle +++ b/backend/build.gradle @@ -45,12 +45,12 @@ dependencies { implementation 'org.flywaydb:flyway-mysql' implementation 'io.github.cdimascio:dotenv-java:3.2.0' implementation 'org.modelmapper:modelmapper:3.2.6' - implementation 'org.springdoc:springdoc-openapi-starter-webmvc-ui:2.9.0' + implementation 'org.springdoc:springdoc-openapi-starter-webmvc-ui:2.9.1' // springdoc(swagger-core-jakarta)이 끌어오는 commons-lang3 3.17.0이 GHSA-j288-q9x7-2f5v // (3.0~3.17.x 취약, 긴 입력 처리 시 무한 재귀)에 걸려 있어 명시적으로 상향. implementation 'org.apache.commons:commons-lang3:3.20.0' implementation 'org.springframework.boot:spring-boot-starter-cache' - implementation 'com.github.ben-manes.caffeine:caffeine:3.2.4' + implementation 'com.github.ben-manes.caffeine:caffeine:3.3.0' implementation 'org.springframework.boot:spring-boot-starter-actuator' // Micrometer 지표를 Prometheus 가 긁어갈 텍스트 형식으로 내보낸다 (/actuator/prometheus). // runtimeOnly 인 이유: 코드가 이 라이브러리를 import 하지 않는다. SessionMetrics 는 @@ -68,7 +68,7 @@ dependencies { // Boot 3.5.16이 관리하는 jackson-databind(2.21.4)가 GHSA-5jmj-h7xm-6q6v(2.19.0~2.21.4 // 취약)에 걸려 있어 이 모듈만 명시적으로 상향(jackson-bom의 나머지 모듈은 그대로 둠). - implementation 'com.fasterxml.jackson.core:jackson-databind:2.22.2' + implementation 'com.fasterxml.jackson.core:jackson-databind:2.22.3' // spring-boot-starter-logging이 끌어오는 log4j-to-slf4j가 log4j-api(2.24.3)를 물고 오는데, // 이게 GHSA(2.13.1~2.25.4 취약, MapMessage.asJson()의 비정상 부동소수점 JSON 직렬화 결함)에 @@ -91,7 +91,7 @@ dependencies { // --- gRPC & Protobuf (버전 정합성 해결) --- def grpcVersion = '1.84.0' - def protobufVersion = '4.36.1' + def protobufVersion = '4.36.2' // Starter는 API만 제공하고 실제 구현체는 아래에서 버전 고정 implementation 'net.devh:grpc-client-spring-boot-starter:3.1.0.RELEASE' @@ -128,7 +128,7 @@ dependencies { protobuf { protoc { - artifact = "com.google.protobuf:protoc:4.36.1" + artifact = "com.google.protobuf:protoc:4.36.2" } plugins { grpc {