ca.uhn.hapi.fhir.changelog.5_7_0.changes.yaml Maven / Gradle / Ivy
---
- item:
type: "add"
title: "The version of a few dependencies have been bumped to the latest versions
(dependent HAPI modules listed in brackets):
- log4j-api (JPA): 2.11.1 -> 2.17.1 (Addresses CVE-2021-44228 - HAPI FHIR was not vulnerable to this issue but this upgrade avoids unnecessary OWASP scan notices)
- SLF4j (All): 1.7.30 -> 1.7.33
- Logback (All): 1.2.8 -> 1.2.10
- Commons-IO (All): 2.8.0 -> 2.11.0
- Jackson (All): 2.13.0 -> 2.13.1
- Guava (All): 30.1.1-jre -> 31.0.1-jre
- JDOM (XML Patch Support): 2.0.6 -> 2.0.6.1 (Addresses CVE-2021-33813)
- Spring (JPA): 5.3.7 -> 5.3.15
- Spring (JPA): 5.3.7 -> 5.3.15
- Spring-Data (JPA): 2.5.0 -> 2.6.1
- Hibernate ORM (JPA): 5.4.30.Final -> 5.6.2.Final
- Flyway (JPA): 6.5.4 -> 8.4.1
- Sqlbuilder (JPA): 3.0.1 -> 3.0.2
- H2 (JPA): 1.4.200 -> 2.1.210 (Note that this change requires the use of the HapiFhirH2Dialect instead of the built-in Hibernate H2Dialect due to Hibernate issue HHH-15002
- Commons-DBCP2 (JPA): .8.0 -> .8.0 -> 2.9.0
- Swagger-Models (OpenAPI Support): 2.1.7 -> 2.1.12
- Thymeleaf (Testpage Overlay): 3.0.12.RELEASE -> 3.0.14.RELEASE (Addresses CVE-2021-43466)
- Commons-CLI (CLI): 1.4 -> 1.5.0
- JANSI (CLI): 2.3.2 -> 2.4.0
- Jetty Server (CLI): 9.4.43.v20210629 -> 9.4.44.v20210927
- Spring Boot (Boot): 2.5.0 -> 2.6.2
- Swagger UI (OpenAPI): 3.46.0 -> 4.1.3
- Resteasy (JAX-RS): 4.0.0.Beta3 -> 5.0.2.Final
- Postgresql (JPA): 42.3.1 -> 42.3.2
- Spring Security Oauth2(Oauth): 2.0.2.RELEASE -> 2.0.17.RELEASE
"
© 2015 - 2025 Weber Informatics LLC | Privacy Policy