bc04637694
Clears jetty CVE-2024-8184/CVE-2024-6763. Pins all Jetty modules via jetty-bom (no skew). Documents residual advisories with no upstream fix (jetty-http 11.x EOL, logback config-file CVEs, jackson WS-2026-0003) as accepted for this loopback daemon. CLAUDE.md: validate CVEs with the jetbrains analyzer (intellij-index is stale after pom edits).
150 lines
6.1 KiB
XML
150 lines
6.1 KiB
XML
<?xml version="1.0" encoding="UTF-8"?>
|
|
<project xmlns="http://maven.apache.org/POM/4.0.0"
|
|
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
|
|
xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
|
|
<modelVersion>4.0.0</modelVersion>
|
|
|
|
<groupId>dev.ltms</groupId>
|
|
<artifactId>bridged</artifactId>
|
|
<version>0.1.0-SNAPSHOT</version>
|
|
<packaging>jar</packaging>
|
|
|
|
<name>bridged</name>
|
|
<description>claude-bridge message server: sole gateway between primary/worker Claude sessions and herdr</description>
|
|
|
|
<properties>
|
|
<maven.compiler.release>25</maven.compiler.release>
|
|
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
|
|
<mainClass>dev.ltms.bridged.Bridged</mainClass>
|
|
|
|
<jackson.version>2.19.0</jackson.version>
|
|
<javalin.version>6.7.0</javalin.version>
|
|
<jetty.version>11.0.25</jetty.version>
|
|
<slf4j.version>2.0.16</slf4j.version>
|
|
<logback.version>1.5.18</logback.version>
|
|
<junit.version>5.11.4</junit.version>
|
|
</properties>
|
|
|
|
<!--
|
|
Dependency security (validate with the JetBrains analyzer's Mend.io check on this pom).
|
|
Deps are pinned to the latest available versions. Residual advisories with NO upstream fix,
|
|
accepted for this loopback-bound daemon that processes no untrusted config:
|
|
- jetty-http 11.0.25 (via Javalin): CVE-2026-2332, CVE-2025-11143 — Jetty 11 is EOL;
|
|
fixed only in Jetty 12, which needs a Javalin major (6.x rides Jetty 11).
|
|
- logback-core 1.5.18: CVE-2025-11226, CVE-2026-1225 — both require a MALICIOUS
|
|
logback.xml (attacker with config write already has code execution); ours is trusted.
|
|
- jackson-core 2.19.0: WS-2026-0003 — "insufficient information", no fixed version published.
|
|
The 11.0.23 -> 11.0.25 bump did clear jetty CVE-2024-8184 (5.9) and CVE-2024-6763.
|
|
-->
|
|
|
|
<!-- Force the latest patched Jetty 11.x across all Javalin-pulled Jetty modules (no version
|
|
skew). Javalin 6.x rides Jetty 11; a move to Jetty 12 needs a Javalin major. -->
|
|
<dependencyManagement>
|
|
<dependencies>
|
|
<dependency>
|
|
<groupId>org.eclipse.jetty</groupId>
|
|
<artifactId>jetty-bom</artifactId>
|
|
<version>${jetty.version}</version>
|
|
<type>pom</type>
|
|
<scope>import</scope>
|
|
</dependency>
|
|
</dependencies>
|
|
</dependencyManagement>
|
|
|
|
<dependencies>
|
|
<!-- JSON + YAML (config, herdr wire format, REST bodies) -->
|
|
<dependency>
|
|
<groupId>com.fasterxml.jackson.core</groupId>
|
|
<artifactId>jackson-databind</artifactId>
|
|
<version>${jackson.version}</version>
|
|
</dependency>
|
|
<dependency>
|
|
<groupId>com.fasterxml.jackson.dataformat</groupId>
|
|
<artifactId>jackson-dataformat-yaml</artifactId>
|
|
<version>${jackson.version}</version>
|
|
</dependency>
|
|
|
|
<!-- REST: the testability surface. MCP tools are thin adapters over these endpoints. -->
|
|
<dependency>
|
|
<groupId>io.javalin</groupId>
|
|
<artifactId>javalin</artifactId>
|
|
<version>${javalin.version}</version>
|
|
</dependency>
|
|
|
|
<!-- Logging -->
|
|
<dependency>
|
|
<groupId>org.slf4j</groupId>
|
|
<artifactId>slf4j-api</artifactId>
|
|
<version>${slf4j.version}</version>
|
|
</dependency>
|
|
<dependency>
|
|
<groupId>ch.qos.logback</groupId>
|
|
<artifactId>logback-classic</artifactId>
|
|
<version>${logback.version}</version>
|
|
</dependency>
|
|
|
|
<!-- Tests -->
|
|
<dependency>
|
|
<groupId>org.junit.jupiter</groupId>
|
|
<artifactId>junit-jupiter</artifactId>
|
|
<version>${junit.version}</version>
|
|
<scope>test</scope>
|
|
</dependency>
|
|
</dependencies>
|
|
|
|
<build>
|
|
<finalName>bridged</finalName>
|
|
<plugins>
|
|
<plugin>
|
|
<groupId>org.apache.maven.plugins</groupId>
|
|
<artifactId>maven-compiler-plugin</artifactId>
|
|
<version>3.14.0</version>
|
|
</plugin>
|
|
|
|
<!-- Unit tests run by default; contract tests (live herdr) are tag-excluded. -->
|
|
<plugin>
|
|
<groupId>org.apache.maven.plugins</groupId>
|
|
<artifactId>maven-surefire-plugin</artifactId>
|
|
<version>3.5.2</version>
|
|
<configuration>
|
|
<excludedGroups>${excludedGroups}</excludedGroups>
|
|
</configuration>
|
|
</plugin>
|
|
|
|
<!-- Runnable fat jar: java -jar target/bridged.jar -->
|
|
<plugin>
|
|
<groupId>org.apache.maven.plugins</groupId>
|
|
<artifactId>maven-shade-plugin</artifactId>
|
|
<version>3.6.0</version>
|
|
<executions>
|
|
<execution>
|
|
<phase>package</phase>
|
|
<goals><goal>shade</goal></goals>
|
|
<configuration>
|
|
<transformers>
|
|
<transformer implementation="org.apache.maven.plugins.shade.resource.ManifestResourceTransformer">
|
|
<mainClass>${mainClass}</mainClass>
|
|
</transformer>
|
|
<transformer implementation="org.apache.maven.plugins.shade.resource.ServicesResourceTransformer"/>
|
|
</transformers>
|
|
</configuration>
|
|
</execution>
|
|
</executions>
|
|
</plugin>
|
|
</plugins>
|
|
</build>
|
|
|
|
<profiles>
|
|
<!-- `mvn test` excludes contract tests. `mvn test -Pcontract` runs them against a live herdr. -->
|
|
<profile>
|
|
<id>default-excludes</id>
|
|
<activation><activeByDefault>true</activeByDefault></activation>
|
|
<properties><excludedGroups>contract</excludedGroups></properties>
|
|
</profile>
|
|
<profile>
|
|
<id>contract</id>
|
|
<properties><excludedGroups/></properties>
|
|
</profile>
|
|
</profiles>
|
|
</project>
|