123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327 |
- <?xml version="1.0" encoding="UTF-8"?>
- <project xmlns="http://maven.apache.org/POM/4.0.0"
- xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
- xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
- <modelVersion>4.0.0</modelVersion>
- <groupId>com.eitc</groupId>
- <artifactId>eitc</artifactId>
- <version>3.8.7</version>
- <name>eitc</name>
- <description>牙科管理系统</description>
- <properties>
- <eitc.version>3.8.7</eitc.version>
- <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
- <project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding>
- <java.version>1.8</java.version>
- <maven-jar-plugin.version>3.1.1</maven-jar-plugin.version>
- <spring-framework.version>5.3.33</spring-framework.version>
- <druid.version>1.2.20</druid.version>
- <bitwalker.version>1.21</bitwalker.version>
- <swagger.version>3.0.0</swagger.version>
- <kaptcha.version>2.3.3</kaptcha.version>
- <pagehelper.boot.version>1.4.7</pagehelper.boot.version>
- <fastjson.version>2.0.43</fastjson.version>
- <oshi.version>6.5.0</oshi.version>
- <commons.io.version>2.13.0</commons.io.version>
- <poi.version>4.1.2</poi.version>
- <velocity.version>2.3</velocity.version>
- <jwt.version>0.9.1</jwt.version>
- </properties>
- <!-- 依赖声明 -->
- <dependencyManagement>
- <dependencies>
- <!-- SpringFramework的依赖配置-->
- <dependency>
- <groupId>org.springframework</groupId>
- <artifactId>spring-framework-bom</artifactId>
- <version>${spring-framework.version}</version>
- <type>pom</type>
- <scope>import</scope>
- </dependency>
- <!-- https://mvnrepository.com/artifact/com.itextpdf/html2pdf -->
- <dependency>
- <groupId>com.itextpdf</groupId>
- <artifactId>html2pdf</artifactId>
- <version>4.0.5</version>
- </dependency>
- <!-- SpringBoot的依赖配置-->
- <dependency>
- <groupId>org.springframework.boot</groupId>
- <artifactId>spring-boot-dependencies</artifactId>
- <version>2.5.15</version>
- <type>pom</type>
- <scope>import</scope>
- </dependency>
- <!--
- Spring Boot 2.5.15的内置版本
- <spring-security.version>5.5.8</spring-security.version>
- 强制修改依赖版本为:5.7.12
- 存在漏洞的JAR包:spring-security-core-5.5.8.jar
- 漏洞说明:Spring Security存在安全漏洞,在处理Authentication参数时没有对null值进行检查。当应用程序直接使用AuthenticatedVoter#vote方法,传入null作为认证参数时会错误地返回true值。攻击者可利用该漏洞绕过身份验证,进行提权或窃取系统敏感信息。
- 安全版本: Spring Security 5.7.12、5.8.11、6.0.10、6.1.8、6.2.3 及以上版本,下载地址:https://github.com/spring-projects/spring-security/releases
- <spring-security.version>5.7.12</spring-security.version>
- 注意:因为使用Maven管理依赖,MAVEN具有依赖传递的特性,实质上只需要引入spring-security-config依赖包含了spring-security-core依赖和spring-security-web依赖
- -->
- <!-- spring-security 漏洞升级 -->
- <dependency>
- <groupId>org.springframework.security</groupId>
- <artifactId>spring-security-config</artifactId>
- <version>5.7.12</version>
- <scope>compile</scope>
- </dependency>
- <dependency>
- <groupId>org.springframework.security</groupId>
- <artifactId>spring-security-core</artifactId>
- <version>5.7.12</version>
- <scope>compile</scope>
- </dependency>
- <dependency>
- <groupId>org.springframework.security</groupId>
- <artifactId>spring-security-crypto</artifactId>
- <version>5.7.12</version>
- <scope>compile</scope>
- </dependency>
- <dependency>
- <groupId>org.springframework.security</groupId>
- <artifactId>spring-security-web</artifactId>
- <version>5.7.12</version>
- <scope>compile</scope>
- </dependency>
- <dependency>
- <groupId>org.quartz-scheduler</groupId>
- <artifactId>quartz</artifactId>
- <version>2.4.0-rc2</version>
- <exclusions>
- <exclusion>
- <groupId>com.mchange</groupId>
- <artifactId>c3p0</artifactId>
- </exclusion>
- </exclusions>
- </dependency>
- <!-- 阿里数据库连接池 -->
- <dependency>
- <groupId>com.alibaba</groupId>
- <artifactId>druid-spring-boot-starter</artifactId>
- <version>${druid.version}</version>
- <exclusions>
- <exclusion>
- <groupId>org.yaml</groupId>
- <artifactId>snakeyaml</artifactId>
- </exclusion>
- </exclusions>
- </dependency>
- <!-- yml解析器 漏洞修复,安全版本2.0及以上:https://mvnrepository.com/artifact/org.yaml/snakeyaml-->
- <!-- 漏洞升级 -->
- <dependency>
- <groupId>org.yaml</groupId>
- <artifactId>snakeyaml</artifactId>
- <version>2.0</version>
- </dependency>
- <!-- 解析客户端操作系统、浏览器等 -->
- <dependency>
- <groupId>eu.bitwalker</groupId>
- <artifactId>UserAgentUtils</artifactId>
- <version>${bitwalker.version}</version>
- </dependency>
- <!-- pagehelper 分页插件 -->
- <dependency>
- <groupId>com.github.pagehelper</groupId>
- <artifactId>pagehelper-spring-boot-starter</artifactId>
- <version>${pagehelper.boot.version}</version>
- </dependency>
- <!-- 获取系统信息 -->
- <dependency>
- <groupId>com.github.oshi</groupId>
- <artifactId>oshi-core</artifactId>
- <version>${oshi.version}</version>
- </dependency>
- <!-- Swagger3依赖 -->
- <dependency>
- <groupId>io.springfox</groupId>
- <artifactId>springfox-boot-starter</artifactId>
- <version>${swagger.version}</version>
- <exclusions>
- <exclusion>
- <groupId>io.swagger</groupId>
- <artifactId>swagger-models</artifactId>
- </exclusion>
- </exclusions>
- </dependency>
- <!-- io常用工具类 -->
- <dependency>
- <groupId>commons-io</groupId>
- <artifactId>commons-io</artifactId>
- <version>${commons.io.version}</version>
- </dependency>
- <!-- excel工具 -->
- <dependency>
- <groupId>org.apache.poi</groupId>
- <artifactId>poi-ooxml</artifactId>
- <version>${poi.version}</version>
- </dependency>
- <!-- velocity代码生成使用模板 -->
- <dependency>
- <groupId>org.apache.velocity</groupId>
- <artifactId>velocity-engine-core</artifactId>
- <version>${velocity.version}</version>
- </dependency>
- <!-- 阿里JSON解析器 -->
- <dependency>
- <groupId>com.alibaba.fastjson2</groupId>
- <artifactId>fastjson2</artifactId>
- <version>${fastjson.version}</version>
- </dependency>
- <!-- Token生成与解析-->
- <dependency>
- <groupId>io.jsonwebtoken</groupId>
- <artifactId>jjwt</artifactId>
- <version>${jwt.version}</version>
- </dependency>
- <!-- 验证码 -->
- <dependency>
- <groupId>pro.fessional</groupId>
- <artifactId>kaptcha</artifactId>
- <version>${kaptcha.version}</version>
- </dependency>
- <!-- mybatis-plus 增强CRUD -->
- <dependency>
- <groupId>com.baomidou</groupId>
- <artifactId>mybatis-plus-boot-starter</artifactId>
- <version>3.5.1</version>
- </dependency>
- <dependency>
- <groupId>org.projectlombok</groupId>
- <artifactId>lombok</artifactId>
- <version>1.18.28</version>
- </dependency>
- <!-- 定时任务-->
- <dependency>
- <groupId>com.eitc</groupId>
- <artifactId>eitc-quartz</artifactId>
- <version>${eitc.version}</version>
- </dependency>
- <!-- 代码生成-->
- <dependency>
- <groupId>com.eitc</groupId>
- <artifactId>eitc-generator</artifactId>
- <version>${eitc.version}</version>
- </dependency>
- <!-- 核心模块-->
- <dependency>
- <groupId>com.eitc</groupId>
- <artifactId>eitc-framework</artifactId>
- <version>${eitc.version}</version>
- </dependency>
- <!-- 系统模块-->
- <dependency>
- <groupId>com.eitc</groupId>
- <artifactId>eitc-system</artifactId>
- <version>${eitc.version}</version>
- </dependency>
- <!-- 通用工具-->
- <dependency>
- <groupId>com.eitc</groupId>
- <artifactId>eitc-common</artifactId>
- <version>${eitc.version}</version>
- </dependency>
- <dependency>
- <groupId>com.eitc</groupId>
- <artifactId>eitc-patient-base</artifactId>
- <version>${eitc.version}</version>
- </dependency>
- <dependency>
- <groupId>com.eitc</groupId>
- <artifactId>eitc-patient-app</artifactId>
- <version>${eitc.version}</version>
- </dependency>
- <dependency>
- <groupId>com.eitc</groupId>
- <artifactId>eitc-patient-pc</artifactId>
- <version>${eitc.version}</version>
- </dependency>
- </dependencies>
- </dependencyManagement>
- <modules>
- <module>eitc-admin</module>
- <module>eitc-framework</module>
- <module>eitc-system</module>
- <module>eitc-quartz</module>
- <module>eitc-generator</module>
- <module>eitc-common</module>
- <module>eitc-patient-base</module>
- <module>eitc-patient-app</module>
- <module>eitc-patient-pc</module>
- </modules>
- <packaging>pom</packaging>
- <build>
- <plugins>
- <plugin>
- <groupId>org.apache.maven.plugins</groupId>
- <artifactId>maven-compiler-plugin</artifactId>
- <version>3.1</version>
- <configuration>
- <source>${java.version}</source>
- <target>${java.version}</target>
- <encoding>${project.build.sourceEncoding}</encoding>
- </configuration>
- </plugin>
- </plugins>
- </build>
- <repositories>
- <repository>
- <id>public</id>
- <name>aliyun nexus</name>
- <url>https://maven.aliyun.com/repository/public</url>
- <releases>
- <enabled>true</enabled>
- </releases>
- </repository>
- </repositories>
- <pluginRepositories>
- <pluginRepository>
- <id>public</id>
- <name>aliyun nexus</name>
- <url>https://maven.aliyun.com/repository/public</url>
- <releases>
- <enabled>true</enabled>
- </releases>
- <snapshots>
- <enabled>false</enabled>
- </snapshots>
- </pluginRepository>
- </pluginRepositories>
- </project>
|