From 1e22eace0be1fb75e7447567576013dc9324c543 Mon Sep 17 00:00:00 2001 From: AWSHurneyt Date: Wed, 28 Feb 2024 16:16:01 -0800 Subject: [PATCH] Forced ktlint to use logback-core:1.2.13, and logback-classic:1.2.13 to address CVE. Signed-off-by: AWSHurneyt --- build.gradle | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/build.gradle b/build.gradle index 6d9fcb29..a42b8272 100644 --- a/build.gradle +++ b/build.gradle @@ -78,7 +78,12 @@ dependencies { testImplementation "com.nhaarman.mockitokotlin2:mockito-kotlin:2.2.0" testRuntimeOnly 'org.junit.jupiter:junit-jupiter-engine:5.7.2' - ktlint "com.pinterest:ktlint:0.45.1" + add("ktlint", "com.pinterest:ktlint:0.45.1") { + exclude group: "ch.qos.logback", module: "logback-classic" + exclude group: "ch.qos.logback", module: "logback-core" + } + add("ktlint", "ch.qos.logback:logback-core:1.2.13") + add("ktlint", "ch.qos.logback:logback-classic:1.2.13") } test {