From d5324409eece8d5e9db929872fbc0eb59dfa7b8a Mon Sep 17 00:00:00 2001 From: ZeyuLi-AWS <125080976+ZeyuLi-AWS@users.noreply.github.com> Date: Thu, 16 Feb 2023 12:51:48 -0800 Subject: [PATCH] Updated the dependency to fix vulnerability issue (#1042) * updated the aws-java-sdk and google.protobuf version to fix vulnerabilities --- CHANGELOG.md | 7 ++++++- pom.xml | 6 +++--- .../lib/worker/KinesisClientLibConfiguration.java | 2 +- 3 files changed, 10 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 205a7401..af32970e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,6 +1,11 @@ # Changelog +### Latest Release (1.14.10 - Feb 15, 2023) +* Updated aws-java-sdk from 1.12.130 to 1.12.406 +* Updated com.google.protobuf from 3.19.4 to 3.19.6 + * [Issue #1026](https://github.com/awslabs/amazon-kinesis-client/issues/1026) + * [PR #1042](https://github.com/awslabs/amazon-kinesis-client/pull/1042) -### Latest Release (1.14.9 - Dec 14, 2022) +### Release (1.14.9 - Dec 14, 2022) * [#995](https://github.com/awslabs/amazon-kinesis-client/commit/372f98b21a91487e36612d528c56765a44b0aa86) Every other change for DynamoDBStreamsKinesis Adapter Compatibility * [#970](https://github.com/awslabs/amazon-kinesis-client/commit/251b331a2e0fd912b50f8b5a12d088bf0b3263b9) PeriodicShardSyncManager Changes Needed for DynamoDBStreamsKinesisAdapter diff --git a/pom.xml b/pom.xml index fcbae8ae..38cabe7a 100644 --- a/pom.xml +++ b/pom.xml @@ -6,7 +6,7 @@ amazon-kinesis-client jar Amazon Kinesis Client Library for Java - 1.14.9 + 1.14.10 The Amazon Kinesis Client Library for Java enables Java developers to easily consume and process data from Amazon Kinesis. @@ -25,7 +25,7 @@ - 1.12.130 + 1.12.406 1.0.392 libsqlite4java ${project.build.directory}/test-lib @@ -60,7 +60,7 @@ com.google.protobuf protobuf-java - 3.19.4 + 3.19.6 org.apache.commons diff --git a/src/main/java/com/amazonaws/services/kinesis/clientlibrary/lib/worker/KinesisClientLibConfiguration.java b/src/main/java/com/amazonaws/services/kinesis/clientlibrary/lib/worker/KinesisClientLibConfiguration.java index acf0aa3e..bf95586a 100644 --- a/src/main/java/com/amazonaws/services/kinesis/clientlibrary/lib/worker/KinesisClientLibConfiguration.java +++ b/src/main/java/com/amazonaws/services/kinesis/clientlibrary/lib/worker/KinesisClientLibConfiguration.java @@ -147,7 +147,7 @@ public class KinesisClientLibConfiguration { /** * User agent set when Amazon Kinesis Client Library makes AWS requests. */ - public static final String KINESIS_CLIENT_LIB_USER_AGENT = "amazon-kinesis-client-library-java-1.14.9"; + public static final String KINESIS_CLIENT_LIB_USER_AGENT = "amazon-kinesis-client-library-java-1.14.10"; /** * KCL will validate client provided sequence numbers with a call to Amazon Kinesis before checkpointing for calls