From ef9985f81121f43c5ebf10164da773f3f43e4bd7 Mon Sep 17 00:00:00 2001 From: Oleksandra Matviienko Date: Mon, 20 Apr 2026 12:41:40 +0200 Subject: [PATCH] Address review comments: group Spring Boot BOM overrides, drop thymeleaf + lz4 plumbing - Group tomcat, commons-lang3 version properties under spring-boot.version - Drop thymeleaf override (PE-only dependency, not present in CE) - Drop lz4 plumbing: kafka-clients 3.9.2 and cassandra-all 5.0.7 now transitively ship at.yawk.lz4:lz4-java, making the Dec 2025 CVE hack obsolete --- common/queue/pom.xml | 4 --- pom.xml | 39 ++-------------------- rule-engine/rule-engine-components/pom.xml | 4 --- tools/pom.xml | 4 --- 4 files changed, 3 insertions(+), 48 deletions(-) diff --git a/common/queue/pom.xml b/common/queue/pom.xml index a7d4d5b568..1cf8320468 100644 --- a/common/queue/pom.xml +++ b/common/queue/pom.xml @@ -68,10 +68,6 @@ org.apache.kafka kafka-clients - - at.yawk.lz4 - lz4-java - com.google.cloud google-cloud-pubsub diff --git a/pom.xml b/pom.xml index 47a971b920..1769b212f8 100755 --- a/pom.xml +++ b/pom.xml @@ -63,6 +63,8 @@ /var/log/${pkg.name} /usr/share/${pkg.name} 3.5.13 + 10.1.54 + 3.18.0 2.4.0-b180830.0359 0.12.5 0.10 @@ -70,8 +72,6 @@ 4.2.25 5.0.7 33.1.0-jre - 10.1.54 - 3.18.0 2.16.1 1.3.1 1.10.0 @@ -103,7 +103,6 @@ 0.8 1.19.0 1.84 - 3.1.4.RELEASE 2.0.1 org/thingsboard/server/gen/**/*, org/thingsboard/server/extensions/core/plugin/telemetry/gen/**/* @@ -113,8 +112,7 @@ - 3.9.2 - 1.10.1 + 3.9.2 8.10.1 3.5.3 1.12.701 @@ -1022,20 +1020,6 @@ ${tomcat.version} - - - org.thymeleaf - thymeleaf - ${thymeleaf.version} - - - org.thymeleaf - thymeleaf-spring6 - ${thymeleaf.version} - - org.springframework.boot spring-boot-dependencies @@ -1286,17 +1270,6 @@ org.apache.kafka kafka-clients ${kafka.version} - - - org.lz4 - lz4-java - - - - - at.yawk.lz4 - lz4-java - ${lz4.version} com.github.springtestdbunit @@ -1572,12 +1545,6 @@ org.apache.cassandra cassandra-all ${cassandra-all.version} - - - org.lz4 - lz4-java - - org.testng diff --git a/rule-engine/rule-engine-components/pom.xml b/rule-engine/rule-engine-components/pom.xml index a156bb22a2..1ac0938163 100644 --- a/rule-engine/rule-engine-components/pom.xml +++ b/rule-engine/rule-engine-components/pom.xml @@ -96,10 +96,6 @@ org.apache.kafka kafka-clients - - at.yawk.lz4 - lz4-java - com.amazonaws aws-java-sdk-sns diff --git a/tools/pom.xml b/tools/pom.xml index 46c56c634b..6376db6d9f 100644 --- a/tools/pom.xml +++ b/tools/pom.xml @@ -73,10 +73,6 @@ - - at.yawk.lz4 - lz4-java - commons-io commons-io