This is an automated email from the ASF dual-hosted git repository.

solomax pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/openmeetings.git


The following commit(s) were added to refs/heads/master by this push:
     new 25a181a83 [OPENMEETINGS-2824] junit, tomcat, asterisk-java and logback
25a181a83 is described below

commit 25a181a83eae8c8b94fa44b1afe693a01cab97ec
Author: Maxim Solodovnik <[email protected]>
AuthorDate: Mon Jul 13 14:54:57 2026 +0700

    [OPENMEETINGS-2824] junit, tomcat, asterisk-java and logback
---
 LICENSE                                            | 41 +++++++------
 openmeetings-server/pom.xml                        |  2 +-
 openmeetings-server/src/site/xdoc/ReleaseGuide.xml | 67 ++++++++++------------
 openmeetings-server/src/site/xdoc/security.xml     | 14 +++++
 openmeetings-web/pom.xml                           |  4 ++
 pom.xml                                            | 13 +++--
 6 files changed, 81 insertions(+), 60 deletions(-)

diff --git a/LICENSE b/LICENSE
index dd5d3cb08..88e470918 100644
--- a/LICENSE
+++ b/LICENSE
@@ -271,10 +271,10 @@ conditions of the following licenses.
         * Jakarta Messaging API (jakarta.jms:jakarta.jms-api:3.1.0 - 
https://projects.eclipse.org/projects/ee4j.jms)
         * Jakarta Persistence API 
(jakarta.persistence:jakarta.persistence-api:3.2.0 - 
https://github.com/jakartaee/persistence)
         * Jakarta RESTful WS API (jakarta.ws.rs:jakarta.ws.rs-api:4.0.0 - 
https://github.com/jakartaee/rest/jakarta.ws.rs-api)
-        * JUnit Jupiter API (org.junit.jupiter:junit-jupiter-api:6.1.1 - 
https://junit.org/)
-        * JUnit Platform Commons 
(org.junit.platform:junit-platform-commons:6.1.1 - https://junit.org/)
-        * Logback Classic Module (ch.qos.logback:logback-classic:1.5.37 - 
http://logback.qos.ch/logback-classic)
-        * Logback Core Module (ch.qos.logback:logback-core:1.5.37 - 
http://logback.qos.ch/logback-core)
+        * JUnit Jupiter API (org.junit.jupiter:junit-jupiter-api:6.1.2 - 
https://junit.org/)
+        * JUnit Platform Commons 
(org.junit.platform:junit-platform-commons:6.1.2 - https://junit.org/)
+        * Logback Classic Module (ch.qos.logback:logback-classic:1.5.38 - 
http://logback.qos.ch/logback-classic)
+        * Logback Core Module (ch.qos.logback:logback-core:1.5.38 - 
http://logback.qos.ch/logback-core)
 
     GENERAL PUBLIC LICENSE, version 3 (GPL-3.0), GNU LESSER GENERAL PUBLIC 
LICENSE, version 3 (LGPL-3.0), Mozilla Public License Version 1.1
 
@@ -396,6 +396,8 @@ conditions of the following licenses.
         * Apache James :: Mime4j :: DOM 
(org.apache.james:apache-mime4j-dom:0.8.14 - 
http://james.apache.org/mime4j/apache-mime4j-dom)
         * Apache JempBox (org.apache.pdfbox:jempbox:1.8.17 - 
http://www.apache.org/pdfbox-parent/jempbox/)
         * Apache Log4j API (org.apache.logging.log4j:log4j-api:2.24.3 - 
https://logging.apache.org/log4j/2.x/log4j/log4j-api/)
+        * Apache Log4j API (org.apache.logging.log4j:log4j-api:2.25.4 - 
https://logging.apache.org/log4j/2.x/)
+        * Apache Log4j Core (org.apache.logging.log4j:log4j-core:2.25.4 - 
https://logging.apache.org/log4j/2.x/)
         * Apache MINA Core (org.apache.mina:mina-core:2.2.3 - 
https://mina.apache.org/mina-core/)
         * Apache MINA Core (org.apache.mina:mina-core:2.2.7 - 
https://mina.apache.org/mina-core/)
         * Apache Neethi (org.apache.neethi:neethi:3.2.2 - 
https://ws.apache.org/neethi/)
@@ -437,7 +439,7 @@ conditions of the following licenses.
         * Apache Wicket IPageStore Hazelcast 
(org.wicketstuff:wicketstuff-datastore-hazelcast:10.9.2 - 
http://wicketstuff.org/datastores-parent/wicketstuff-datastore-hazelcast)
         * Apache XBean :: ASM shaded (repackaged) 
(org.apache.xbean:xbean-asm9-shaded:4.26 - 
http://geronimo.apache.org/maven/xbean/4.26/xbean-asm9-shaded)
         * Apache XmpBox (org.apache.pdfbox:xmpbox:3.0.7 - 
https://www.apache.org/pdfbox-parent/xmpbox/)
-        * Asterisk-Java (org.asteriskjava:asterisk-java:3.41.0 - 
https://github.com/asterisk-java/asterisk-java)
+        * Asterisk-Java (org.asteriskjava:asterisk-java:3.42.2 - 
https://github.com/asterisk-java/asterisk-java)
         * Bootstrap (org.webjars:bootstrap:5.3.8 - http://webjars.org)
         * bootstrap-core (de.agilecoders.wicket:wicket-bootstrap-core:7.0.14 - 
https://github.com/l0rdn1kk0n/wicket-bootstrap/wicket-bootstrap-core)
         * bootstrap-extensions 
(de.agilecoders.wicket:wicket-bootstrap-extensions:7.0.14 - 
https://github.com/l0rdn1kk0n/wicket-bootstrap/wicket-bootstrap-extensions)
@@ -449,17 +451,17 @@ conditions of the following licenses.
         * com.drewnoakes:metadata-extractor 
(com.drewnoakes:metadata-extractor:2.20.0 - https://drewnoakes.com/code/exif/)
         * core (org.kurento:kms-api-core:7.3.0 - https://kurento.openvidu.io/)
         * elements (org.kurento:kms-api-elements:7.3.0 - 
https://kurento.openvidu.io/)
-        * error-prone annotations 
(com.google.errorprone:error_prone_annotations:2.28.0 - 
https://errorprone.info/error_prone_annotations)
+        * error-prone annotations 
(com.google.errorprone:error_prone_annotations:2.41.0 - 
https://errorprone.info/error_prone_annotations)
         * error-prone annotations 
(com.google.errorprone:error_prone_annotations:2.48.0 - 
https://errorprone.info/error_prone_annotations)
         * filters (org.kurento:kms-api-filters:7.3.0 - 
https://kurento.openvidu.io/)
         * FindBugs-jsr305 (com.google.code.findbugs:jsr305:3.0.2 - 
http://findbugs.sourceforge.net/)
         * Gson (com.google.code.gson:gson:2.14.0 - 
https://github.com/google/gson)
         * Gson (com.google.code.gson:gson:2.9.1 - 
https://github.com/google/gson/gson)
-        * Guava: Google Core Libraries for Java 
(com.google.guava:guava:33.3.1-jre - https://github.com/google/guava)
-        * Guava InternalFutureFailureAccess and InternalFutures 
(com.google.guava:failureaccess:1.0.2 - 
https://github.com/google/guava/failureaccess)
+        * Guava: Google Core Libraries for Java 
(com.google.guava:guava:33.5.0-jre - https://github.com/google/guava)
+        * Guava InternalFutureFailureAccess and InternalFutures 
(com.google.guava:failureaccess:1.0.3 - 
https://github.com/google/guava/failureaccess)
         * Guava ListenableFuture only 
(com.google.guava:listenablefuture:9999.0-empty-to-avoid-conflict-with-guava - 
https://github.com/google/guava/listenablefuture)
         * hazelcast (com.hazelcast:hazelcast:5.7.0 - 
http://www.hazelcast.com/hazelcast/)
-        * J2ObjC Annotations (com.google.j2objc:j2objc-annotations:3.0.0 - 
https://github.com/google/j2objc/)
+        * J2ObjC Annotations (com.google.j2objc:j2objc-annotations:3.1 - 
https://github.com/google/j2objc/)
         * Jackcess (com.healthmarketscience.jackcess:jackcess:4.0.10 - 
https://jackcess.sourceforge.io)
         * Jackcess Encrypt 
(com.healthmarketscience.jackcess:jackcess-encrypt:4.0.3 - 
http://jackcessencrypt.sf.net)
         * Jackson-annotations 
(com.fasterxml.jackson.core:jackson-annotations:2.17.2 - 
https://github.com/FasterXML/jackson)
@@ -509,21 +511,22 @@ conditions of the following licenses.
         * Ogg and Vorbis for Java, Core (org.gagravarr:vorbis-java-core:0.8 - 
https://github.com/Gagravarr/VorbisJava)
         * OpenJPA Aggregate Jar (org.apache.openjpa:openjpa:4.1.1 - 
http://openjpa.apache.org/openjpa)
         * Open JSON (com.github.openjson:openjson:1.0.13 - 
https://github.com/openjson/openjson)
-        * Openmeetings Core 
(org.apache.openmeetings:openmeetings-core:9.1.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-core)
-        * Openmeetings DB 
(org.apache.openmeetings:openmeetings-db:9.1.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-db)
-        * Openmeetings Install 
(org.apache.openmeetings:openmeetings-install:9.1.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-install)
-        * Openmeetings MediaServer 
(org.apache.openmeetings:openmeetings-mediaserver:9.1.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-mediaserver)
-        * Openmeetings Screen Sharing applet 
(org.apache.openmeetings:openmeetings-screenshare:9.1.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-screenshare)
-        * Openmeetings Service 
(org.apache.openmeetings:openmeetings-service:9.1.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-service)
-        * Openmeetings Util 
(org.apache.openmeetings:openmeetings-util:9.1.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-util)
-        * Openmeetings Web 
(org.apache.openmeetings:openmeetings-web:9.1.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-web)
-        * Openmeetings Webservices 
(org.apache.openmeetings:openmeetings-webservice:9.1.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-webservice)
+        * Openmeetings Core 
(org.apache.openmeetings:openmeetings-core:9.2.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-core)
+        * Openmeetings DB 
(org.apache.openmeetings:openmeetings-db:9.2.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-db)
+        * Openmeetings Install 
(org.apache.openmeetings:openmeetings-install:9.2.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-install)
+        * Openmeetings MediaServer 
(org.apache.openmeetings:openmeetings-mediaserver:9.2.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-mediaserver)
+        * Openmeetings Screen Sharing applet 
(org.apache.openmeetings:openmeetings-screenshare:9.2.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-screenshare)
+        * Openmeetings Service 
(org.apache.openmeetings:openmeetings-service:9.2.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-service)
+        * Openmeetings Util 
(org.apache.openmeetings:openmeetings-util:9.2.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-util)
+        * Openmeetings Web 
(org.apache.openmeetings:openmeetings-web:9.2.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-web)
+        * Openmeetings Webservices 
(org.apache.openmeetings:openmeetings-webservice:9.2.0-SNAPSHOT - 
https://openmeetings.apache.org/openmeetings-webservice)
         * org.apiguardian:apiguardian-api 
(org.apiguardian:apiguardian-api:1.1.2 - 
https://github.com/apiguardian-team/apiguardian)
         * org.opentest4j:opentest4j (org.opentest4j:opentest4j:1.3.0 - 
https://github.com/ota4j-team/opentest4j)
         * OWASP Java HTML Sanitizer 
(com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer:20260313.1 
- https://github.com/OWASP/java-html-sanitizer)
         * parso (com.epam:parso:2.0.14 - https://github.com/epam/parso)
         * PDFBox JBIG2 ImageIO plugin (org.apache.pdfbox:jbig2-imageio:3.0.5 - 
https://www.apache.org/jbig2-imageio/)
         * picocli (info.picocli:picocli:4.7.7 - https://picocli.info)
+        * Prometheus Metrics Annotations 
(io.prometheus:prometheus-metrics-annotations:1.8.0 - 
http://github.com/prometheus/client_java/client_java/prometheus-metrics-annotations)
         * Prometheus Metrics Config 
(io.prometheus:prometheus-metrics-config:1.8.0 - 
http://github.com/prometheus/client_java/client_java/prometheus-metrics-config)
         * Prometheus Metrics Core (io.prometheus:prometheus-metrics-core:1.8.0 
- http://github.com/prometheus/client_java/client_java/prometheus-metrics-core)
         * Prometheus Metrics Exporter - Common 
(io.prometheus:prometheus-metrics-exporter-common:1.8.0 - 
http://github.com/prometheus/client_java/client_java/prometheus-metrics-exporter-common)
@@ -552,7 +555,7 @@ conditions of the following licenses.
         * Spring Web (org.springframework:spring-web:7.0.8 - 
https://github.com/spring-projects/spring-framework)
         * Spring Web MVC (org.springframework:spring-webmvc:7.0.8 - 
https://github.com/spring-projects/spring-framework)
         * swagger-annotations (io.swagger.core.v3:swagger-annotations:2.2.52 - 
https://github.com/swagger-api/swagger-core/modules/swagger-annotations)
-        * tomcat (org.apache.tomcat:tomcat:11.0.23 - 
https://tomcat.apache.org/)
+        * tomcat (org.apache.tomcat:tomcat:11.0.24 - 
https://tomcat.apache.org/)
         * UNO interface library (org.openoffice:unoil:4.1.2 - 
https://wiki.openoffice.org/wiki/Uno)
         * Wicket Auth Roles (org.apache.wicket:wicket-auth-roles:10.9.1 - 
http://wicket.apache.org/wicket-auth-roles)
         * Wicket Core (org.apache.wicket:wicket-core:10.9.1 - 
http://wicket.apache.org/wicket-core)
diff --git a/openmeetings-server/pom.xml b/openmeetings-server/pom.xml
index 09ae68fc3..e3e0f7417 100644
--- a/openmeetings-server/pom.xml
+++ b/openmeetings-server/pom.xml
@@ -46,7 +46,7 @@
        <scm>
                
<connection>scm:git:https://github.com/apache/openmeetings.git</connection>
                
<developerConnection>scm:git:https://github.com/apache/openmeetings.git</developerConnection>
-               <url>https://github.com/apache/openmeetings/tree/9.0.0</url>
+               <url>https://github.com/apache/openmeetings</url>
                <tag>HEAD</tag>
        </scm>
        <profiles>
diff --git a/openmeetings-server/src/site/xdoc/ReleaseGuide.xml 
b/openmeetings-server/src/site/xdoc/ReleaseGuide.xml
index c03198189..59777a371 100644
--- a/openmeetings-server/src/site/xdoc/ReleaseGuide.xml
+++ b/openmeetings-server/src/site/xdoc/ReleaseGuide.xml
@@ -120,30 +120,25 @@
                                                <source>git checkout 
master</source>
                                        </li>
                                        <li>Create temporary local branch
-                                               <source>git checkout -b 
rel-8.2.0</source>
+                                               <source>git checkout -b 
rel-9.2.0</source>
                                        </li>
                                        <li>Update versions of all modules
-                                               <source>mvn versions:set 
-DgenerateBackupPoms=false -DnewVersion=8.2.0</source>
+                                               <source>mvn versions:set 
-DgenerateBackupPoms=false -DnewVersion=9.2.0</source>
                                        </li>
                                        <li>Update final SCM URL located at 
<code>pom.xml</code> and <code>openmeetings-server/pom.xml</code>
                                                <source><![CDATA[
 <scm>
     <url>https://github.com/apache/openmeetings        </url>
 
-    SET https://github.com/apache/openmeetings/tree/8.2.0
+    SET https://github.com/apache/openmeetings/tree/9.2.0
                                                ]]></source>
                                        </li>
-                                       <li>Add timestamp to parent pom 
(properties section)
-                                               <source>
-                                                       
<project.build.outputTimestamp>YEAR-MONTH-DAY_OF_MONTHT00:00:00Z</project.build.outputTimestamp>
-                                               </source>
-                                       </li>
                                        <li>
                                                Create a TAG and commit it to 
the Git<br/>
                                                <source>
-git commit -a -m "8.2.0 Release Candidate 1"
-git tag -s 8.2.0-RC1 -m "8.2.0 Release Candidate 1 tag"
-git push origin 8.2.0-RC1
+git commit -a -m "9.2.0 Release Candidate 1"
+git tag -s 9.2.0-RC1 -m "9.2.0 Release Candidate 1 tag"
+git push origin 9.2.0-RC1
                                                </source>
                                        </li>
                                        <li>
@@ -152,7 +147,7 @@ git push origin 8.2.0-RC1
                                        </li>
                                        <li>Go to: <a 
href="https://repository.apache.org/#stagingRepositories";>Staging 
Repositories</a></li>
                                        <li>Select openmeetings staging repo 
and Close it with valid message:<br/>
-                                               for ex. "8.2.0 build was 
successful"
+                                               for ex. "9.2.0 build was 
successful"
                                        </li>
                                        <li>
                                                <p>Run the command: </p>
@@ -166,26 +161,26 @@ git push origin 8.2.0-RC1
                                                <p>
                                                        Commit artifacts you 
have created with KEYS file to the
                                                        
<code>https://dist.apache.org/repos/dist/dev/openmeetings/</code>
-                                                       Proposed file structure 
for "Release Candidate 1" of 8.2.0 will be:
+                                                       Proposed file structure 
for "Release Candidate 1" of 9.2.0 will be:
                                                </p>
                                                <source>
-8.2.0
-8.2.0/rc1
-8.2.0/rc1/src
-8.2.0/rc1/src/apache-openmeetings-8.2.0-src.zip
-8.2.0/rc1/src/apache-openmeetings-8.2.0-src.tar.gz
-8.2.0/rc1/src/apache-openmeetings-8.2.0-src.zip.sha
-8.2.0/rc1/src/apache-openmeetings-8.2.0-src.zip.asc
-8.2.0/rc1/src/apache-openmeetings-8.2.0-src.tar.gz.sha
-8.2.0/rc1/src/apache-openmeetings-8.2.0-src.tar.gz.asc
-8.2.0/rc1/bin
-8.2.0/rc1/bin/apache-openmeetings-8.2.0.zip
-8.2.0/rc1/bin/apache-openmeetings-8.2.0.tar.gz
-8.2.0/rc1/bin/apache-openmeetings-8.2.0.zip.sha
-8.2.0/rc1/bin/apache-openmeetings-8.2.0.zip.asc
-8.2.0/rc1/bin/apache-openmeetings-8.2.0.tar.gz.sha
-8.2.0/rc1/bin/apache-openmeetings-8.2.0.tar.gz.asc
-8.2.0/rc1/CHANGELOG
+9.2.0
+9.2.0/rc1
+9.2.0/rc1/src
+9.2.0/rc1/src/apache-openmeetings-9.2.0-src.zip
+9.2.0/rc1/src/apache-openmeetings-9.2.0-src.tar.gz
+9.2.0/rc1/src/apache-openmeetings-9.2.0-src.zip.sha
+9.2.0/rc1/src/apache-openmeetings-9.2.0-src.zip.asc
+9.2.0/rc1/src/apache-openmeetings-9.2.0-src.tar.gz.sha
+9.2.0/rc1/src/apache-openmeetings-9.2.0-src.tar.gz.asc
+9.2.0/rc1/bin
+9.2.0/rc1/bin/apache-openmeetings-9.2.0.zip
+9.2.0/rc1/bin/apache-openmeetings-9.2.0.tar.gz
+9.2.0/rc1/bin/apache-openmeetings-9.2.0.zip.sha
+9.2.0/rc1/bin/apache-openmeetings-9.2.0.zip.asc
+9.2.0/rc1/bin/apache-openmeetings-9.2.0.tar.gz.sha
+9.2.0/rc1/bin/apache-openmeetings-9.2.0.tar.gz.asc
+9.2.0/rc1/CHANGELOG
                                                </source>
                                                <p><b>NOTE</b> KEYS file is 
located at https://www.apache.org/dist/openmeetings/KEYS and should be just 
updated</p>
                                        </li>
@@ -231,8 +226,8 @@ mvn clean install -Prc,release
                                        <li>Go to <a 
href="https://securesigning.pki.digicert.com/csportal";>https://securesigning.pki.digicert.com/csportal</a></li>
                                        <li>Select "Signing Sets"</li>
                                        <li>Select "Add signing set"</li>
-                                       <li>Enter "Signing set name" (must 
include "Apache OpenMeetings" and version) for ex. "Apache OpenMeetings 
8.2.0-RELEASE"</li>
-                                       <li>Enter "Version" for ex. 
"8.2.0-RELEASE"</li>
+                                       <li>Enter "Signing set name" (must 
include "Apache OpenMeetings" and version) for ex. "Apache OpenMeetings 
9.2.0-RELEASE"</li>
+                                       <li>Enter "Version" for ex. 
"9.2.0-RELEASE"</li>
                                        <li>Select "Java Signing Sha256" as 
"Signing service"</li>
                                        <li>Select "Upload files" and add all 
<b>jar</b> files from <code>target/jnlp</code></li>
                                        <li>Select "Sign now"</li>
@@ -280,9 +275,9 @@ for f in `ls -1 *.tar.gz *.zip`; do gpg --verify $f.asc; 
done
                                <p>Release tag based on RCXX should finally be 
created</p>
                                <source>
 <![CDATA[
-git checkout 8.2.0-RC1
-git tag -s 8.2.0 -m "8.2.0 Release tag"
-git push origin 8.2.0
+git checkout 9.2.0-RC1
+git tag -s 9.2.0 -m "9.2.0 Release tag"
+git push origin 9.2.0
 ]]>
                                </source>
                        </subsection>
@@ -296,7 +291,7 @@ git push origin 8.2.0
                                                <ul>
                                                        <li>Go to: <a 
href="https://repository.apache.org/#stagingRepositories";>Staging 
Repositories</a></li>
                                                        <li>Select openmeetings 
staging repo and Release it with valid message:<br/>
-                                                               for ex. "The 
VOTE about 8.2.0 release was successful"
+                                                               for ex. "The 
VOTE about 9.2.0 release was successful"
                                                        </li>
                                                </ul>
                                        </li>
diff --git a/openmeetings-server/src/site/xdoc/security.xml 
b/openmeetings-server/src/site/xdoc/security.xml
index ddec4e737..fab90468b 100644
--- a/openmeetings-server/src/site/xdoc/security.xml
+++ b/openmeetings-server/src/site/xdoc/security.xml
@@ -52,6 +52,20 @@
                                Please NOTE: only security issues should be 
reported to this list.
                        </p>
                </section>
+               <section name="CVE-2026-49488: Apache OpenMeetings: Arbitrary 
File Read">
+                       <p>Severity: critical</p>
+                       <p>Vendor: The Apache Software Foundation</p>
+                       <p>Versions Affected: Apache OpenMeetings: from 5.0.0 
before 9.1.0.</p>
+                       <p>Description: Improper Limitation of a Pathname to a 
Restricted Directory ('Path Traversal') vulnerability in Apache 
OpenMeetings.<br/>
+                               <br/>
+                               An attacker with moderator rights in any room 
can read arbitrary files accessible to the OS account running the OM server,
+                               including credentials and secrets, via a 
crafted download request.<br/>
+                               <a 
href="https://www.cve.org/CVERecord?id=CVE-2026-49488";>CVE-2026-49488</a>
+                       </p>
+                       <p>The issue was fixed in 9.1.0<br/>
+                               All users are recommended to upgrade to Apache 
OpenMeetings 9.1.0</p>
+                       <p>Credit: This issue was identified by follycat and 
Y0n3er</p>
+               </section>
                <section name="CVE-2026-33005: Apache OpenMeetings: 
Insufficient checks in FileWebService">
                        <p>Severity: moderate</p>
                        <p>Vendor: The Apache Software Foundation</p>
diff --git a/openmeetings-web/pom.xml b/openmeetings-web/pom.xml
index e6748f194..85f025b60 100644
--- a/openmeetings-web/pom.xml
+++ b/openmeetings-web/pom.xml
@@ -526,6 +526,10 @@
                        <groupId>org.junit.jupiter</groupId>
                        <artifactId>junit-jupiter-params</artifactId>
                </dependency>
+               <dependency>
+                       <groupId>io.prometheus</groupId>
+                       <artifactId>prometheus-metrics-annotations</artifactId>
+               </dependency>
                <dependency>
                        <groupId>io.prometheus</groupId>
                        
<artifactId>prometheus-metrics-exporter-servlet-jakarta</artifactId>
diff --git a/pom.xml b/pom.xml
index 0b4035c51..0e35ccd0e 100644
--- a/pom.xml
+++ b/pom.xml
@@ -85,13 +85,13 @@
                <spdx.version>1.0.4</spdx.version>
 
                <!-- dependency versions -->
-               <junit.version>6.1.1</junit.version>
+               <junit.version>6.1.2</junit.version>
                <wicket.version>10.9.1</wicket.version>
                <wicketstuff.version>10.9.2</wicketstuff.version>
                <wicket-bootstrap.version>7.0.14</wicket-bootstrap.version>
                <fullcalendar.version>6.1.20</fullcalendar.version>
                <spring.version>7.0.8</spring.version>
-               <tomcat.version>11.0.23</tomcat.version>
+               <tomcat.version>11.0.24</tomcat.version>
                <jetty.version>11.0.26</jetty.version>
                <ical4j.version>4.3.0</ical4j.version>
                <cxf.version>4.2.2</cxf.version>
@@ -108,7 +108,7 @@
                <jakarta.annotation.version>3.0.0</jakarta.annotation.version>
                
<jakarta.websocket-api.version>2.2.0</jakarta.websocket-api.version>
                <jakarta.servlet-api.version>6.1.0</jakarta.servlet-api.version>
-               <asterisk-java.version>3.41.0</asterisk-java.version>
+               <asterisk-java.version>3.42.2</asterisk-java.version>
                <commons-lang3.version>3.20.0</commons-lang3.version>
                <commons-dbcp.version>2.14.0</commons-dbcp.version>
                <commons-pool2.version>2.13.1</commons-pool2.version>
@@ -129,7 +129,7 @@
                <jackrabbit-webdav.version>2.21.22</jackrabbit-webdav.version>
                <tika-parsers.version>3.3.1</tika-parsers.version>
                <slf4j.version>2.0.18</slf4j.version>
-               <logback.version>1.5.37</logback.version>
+               <logback.version>1.5.38</logback.version>
                <license.excludedScopes>test</license.excludedScopes>
                <bcprov.version>1.84</bcprov.version>
                <mockito.version>5.23.0</mockito.version>
@@ -586,6 +586,11 @@
                                <artifactId>cxf-rt-features-logging</artifactId>
                                <version>${cxf.version}</version>
                        </dependency>
+                       <dependency>
+                               <groupId>io.prometheus</groupId>
+                               
<artifactId>prometheus-metrics-annotations</artifactId>
+                               <version>${io.prometheus.version}</version>
+                       </dependency>
                        <dependency>
                                <groupId>io.prometheus</groupId>
                                <artifactId>prometheus-metrics-core</artifactId>

Reply via email to