pom.xml 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370
  1. <?xml version="1.0" encoding="UTF-8"?>
  2. <project xmlns="http://maven.apache.org/POM/4.0.0"
  3. xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
  4. xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
  5. <modelVersion>4.0.0</modelVersion>
  6. <groupId>com.ruoyi</groupId>
  7. <artifactId>ruoyi</artifactId>
  8. <version>3.8.7</version>
  9. <name>ruoyi</name>
  10. <url>http://www.ruoyi.vip</url>
  11. <description>若依管理系统</description>
  12. <properties>
  13. <ruoyi.version>3.8.7</ruoyi.version>
  14. <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
  15. <project.reporting.outputEncoding>UTF-8</project.reporting.outputEncoding>
  16. <java.version>1.8</java.version>
  17. <maven-jar-plugin.version>3.1.1</maven-jar-plugin.version>
  18. <druid.version>1.2.20</druid.version>
  19. <bitwalker.version>1.21</bitwalker.version>
  20. <swagger.version>3.0.0</swagger.version>
  21. <kaptcha.version>2.3.3</kaptcha.version>
  22. <pagehelper.boot.version>1.4.7</pagehelper.boot.version>
  23. <fastjson.version>2.0.43</fastjson.version>
  24. <oshi.version>6.4.8</oshi.version>
  25. <commons.io.version>2.13.0</commons.io.version>
  26. <commons.collections.version>3.2.2</commons.collections.version>
  27. <poi.version>4.1.2</poi.version>
  28. <velocity.version>2.3</velocity.version>
  29. <jwt.version>0.9.1</jwt.version>
  30. <snakeyaml.version>2.0</snakeyaml.version>
  31. <!--
  32. Spring Boot 2.5.15的内置版本
  33. <spring-security.version>5.5.8</spring-security.version>
  34. 强制修改依赖版本为:5.7.12
  35. 存在漏洞的JAR包:spring-security-core-5.5.8.jar
  36. 漏洞说明:Spring Security存在安全漏洞,在处理Authentication参数时没有对null值进行检查。当应用程序直接使用AuthenticatedVoter#vote方法,传入null作为认证参数时会错误地返回true值。攻击者可利用该漏洞绕过身份验证,进行提权或窃取系统敏感信息。
  37. 安全版本: Spring Security 5.7.12、5.8.11、6.0.10、6.1.8、6.2.3 及以上版本,下载地址:https://github.com/spring-projects/spring-security/releases
  38. <spring-security.version>5.7.12</spring-security.version>
  39. 注意:因为使用Maven管理依赖,MAVEN具有依赖传递的特性,实质上只需要引入spring-security-config依赖包含了spring-security-core依赖和spring-security-web依赖
  40. -->
  41. </properties>
  42. <!-- 依赖声明 -->
  43. <dependencyManagement>
  44. <dependencies>
  45. <!-- SpringBoot的依赖配置-->
  46. <dependency>
  47. <groupId>org.springframework.boot</groupId>
  48. <artifactId>spring-boot-dependencies</artifactId>
  49. <version>2.5.15</version>
  50. <type>pom</type>
  51. <scope>import</scope>
  52. </dependency>
  53. <!--
  54. Spring Boot 2.5.15的内置版本
  55. <spring-security.version>5.5.8</spring-security.version>
  56. 强制修改依赖版本为:5.7.12
  57. 存在漏洞的JAR包:spring-security-core-5.5.8.jar
  58. 漏洞说明:Spring Security存在安全漏洞,在处理Authentication参数时没有对null值进行检查。当应用程序直接使用AuthenticatedVoter#vote方法,传入null作为认证参数时会错误地返回true值。攻击者可利用该漏洞绕过身份验证,进行提权或窃取系统敏感信息。
  59. 安全版本: Spring Security 5.7.12、5.8.11、6.0.10、6.1.8、6.2.3 及以上版本,下载地址:https://github.com/spring-projects/spring-security/releases
  60. -->
  61. <!-- spring security 安全认证-->
  62. <dependency>
  63. <groupId>org.springframework.boot</groupId>
  64. <artifactId>spring-boot-starter-security</artifactId>
  65. <version>2.5.15</version>
  66. <exclusions>
  67. <exclusion>
  68. <groupId>org.springframework.security</groupId>
  69. <artifactId>spring-security-config</artifactId>
  70. </exclusion>
  71. <exclusion>
  72. <groupId>org.springframework.security</groupId>
  73. <artifactId>spring-security-core</artifactId>
  74. </exclusion>
  75. <exclusion>
  76. <groupId>org.springframework.security</groupId>
  77. <artifactId>spring-security-crypto</artifactId>
  78. </exclusion>
  79. <exclusion>
  80. <groupId>org.springframework.security</groupId>
  81. <artifactId>spring-security-web</artifactId>
  82. </exclusion>
  83. </exclusions>
  84. </dependency>
  85. <dependency>
  86. <groupId>org.springframework.security</groupId>
  87. <artifactId>spring-security-config</artifactId>
  88. <version>5.7.12</version>
  89. <scope>compile</scope>
  90. </dependency>
  91. <dependency>
  92. <groupId>org.springframework.security</groupId>
  93. <artifactId>spring-security-core</artifactId>
  94. <version>5.7.12</version>
  95. <scope>compile</scope>
  96. </dependency>
  97. <dependency>
  98. <groupId>org.springframework.security</groupId>
  99. <artifactId>spring-security-crypto</artifactId>
  100. <version>5.7.12</version>
  101. <scope>compile</scope>
  102. </dependency>
  103. <dependency>
  104. <groupId>org.springframework.security</groupId>
  105. <artifactId>spring-security-web</artifactId>
  106. <version>5.7.12</version>
  107. <scope>compile</scope>
  108. </dependency>
  109. <!-- 阿里数据库连接池 -->
  110. <dependency>
  111. <groupId>com.alibaba</groupId>
  112. <artifactId>druid-spring-boot-starter</artifactId>
  113. <version>${druid.version}</version>
  114. </dependency>
  115. <!-- 解析客户端操作系统、浏览器等 -->
  116. <dependency>
  117. <groupId>eu.bitwalker</groupId>
  118. <artifactId>UserAgentUtils</artifactId>
  119. <version>${bitwalker.version}</version>
  120. </dependency>
  121. <!-- pagehelper 分页插件 -->
  122. <dependency>
  123. <groupId>com.github.pagehelper</groupId>
  124. <artifactId>pagehelper-spring-boot-starter</artifactId>
  125. <version>${pagehelper.boot.version}</version>
  126. </dependency>
  127. <!-- 获取系统信息 -->
  128. <dependency>
  129. <groupId>com.github.oshi</groupId>
  130. <artifactId>oshi-core</artifactId>
  131. <version>${oshi.version}</version>
  132. </dependency>
  133. <!-- Swagger3依赖 -->
  134. <dependency>
  135. <groupId>io.springfox</groupId>
  136. <artifactId>springfox-boot-starter</artifactId>
  137. <version>${swagger.version}</version>
  138. <exclusions>
  139. <exclusion>
  140. <groupId>io.swagger</groupId>
  141. <artifactId>swagger-models</artifactId>
  142. </exclusion>
  143. </exclusions>
  144. </dependency>
  145. <!-- io常用工具类 -->
  146. <dependency>
  147. <groupId>commons-io</groupId>
  148. <artifactId>commons-io</artifactId>
  149. <version>${commons.io.version}</version>
  150. </dependency>
  151. <!-- excel工具 -->
  152. <dependency>
  153. <groupId>org.apache.poi</groupId>
  154. <artifactId>poi-ooxml</artifactId>
  155. <version>${poi.version}</version>
  156. </dependency>
  157. <dependency>
  158. <groupId>org.apache.poi</groupId>
  159. <artifactId>poi-ooxml-schemas</artifactId>
  160. <version>${poi.version}</version>
  161. </dependency>
  162. <dependency>
  163. <groupId>org.apache.poi</groupId>
  164. <artifactId>poi</artifactId>
  165. <version>${poi.version}</version>
  166. </dependency>
  167. <!-- velocity代码生成使用模板 -->
  168. <dependency>
  169. <groupId>org.apache.velocity</groupId>
  170. <artifactId>velocity-engine-core</artifactId>
  171. <version>${velocity.version}</version>
  172. </dependency>
  173. <!-- collections工具类 -->
  174. <dependency>
  175. <groupId>commons-collections</groupId>
  176. <artifactId>commons-collections</artifactId>
  177. <version>${commons.collections.version}</version>
  178. </dependency>
  179. <!-- 阿里JSON解析器 -->
  180. <dependency>
  181. <groupId>com.alibaba.fastjson2</groupId>
  182. <artifactId>fastjson2</artifactId>
  183. <version>${fastjson.version}</version>
  184. </dependency>
  185. <!-- Token生成与解析-->
  186. <dependency>
  187. <groupId>io.jsonwebtoken</groupId>
  188. <artifactId>jjwt</artifactId>
  189. <version>${jwt.version}</version>
  190. </dependency>
  191. <!-- 验证码 -->
  192. <dependency>
  193. <groupId>pro.fessional</groupId>
  194. <artifactId>kaptcha</artifactId>
  195. <version>${kaptcha.version}</version>
  196. </dependency>
  197. <!-- 定时任务-->
  198. <dependency>
  199. <groupId>com.ruoyi</groupId>
  200. <artifactId>ruoyi-quartz</artifactId>
  201. <version>${ruoyi.version}</version>
  202. </dependency>
  203. <!-- 岗检模块
  204. -->
  205. <dependency>
  206. <groupId>com.ruoyi</groupId>
  207. <artifactId>ruoyi-postcheck</artifactId>
  208. <version>${ruoyi.version}</version>
  209. </dependency>
  210. <!-- 代码生成-->
  211. <dependency>
  212. <groupId>com.ruoyi</groupId>
  213. <artifactId>ruoyi-generator</artifactId>
  214. <version>${ruoyi.version}</version>
  215. </dependency>
  216. <!-- 核心模块-->
  217. <dependency>
  218. <groupId>com.ruoyi</groupId>
  219. <artifactId>ruoyi-framework</artifactId>
  220. <version>${ruoyi.version}</version>
  221. </dependency>
  222. <!-- 系统模块-->
  223. <dependency>
  224. <groupId>com.ruoyi</groupId>
  225. <artifactId>ruoyi-system</artifactId>
  226. <version>${ruoyi.version}</version>
  227. </dependency>
  228. <!-- 通用工具-->
  229. <dependency>
  230. <groupId>com.ruoyi</groupId>
  231. <artifactId>ruoyi-common</artifactId>
  232. <version>${ruoyi.version}</version>
  233. </dependency>
  234. <dependency>
  235. <groupId>org.projectlombok</groupId>
  236. <artifactId>lombok</artifactId>
  237. <version>1.18.28</version>
  238. </dependency>
  239. <!--
  240. yml解析器
  241. 漏洞修复,安全版本2.0及以上:https://mvnrepository.com/artifact/org.yaml/snakeyaml
  242. -->
  243. <dependency>
  244. <groupId>org.yaml</groupId>
  245. <artifactId>snakeyaml</artifactId>
  246. <version>2.0</version>
  247. </dependency>
  248. <!--
  249. JSON工具类
  250. 漏洞升级
  251. <dependency>
  252. <groupId>com.fasterxml.jackson.core</groupId>
  253. <artifactId>jackson-databind</artifactId>
  254. <version>2.15.2</version>
  255. <version>2.13.1</version>
  256. </dependency>
  257. -->
  258. <!--
  259. 定时任务
  260. 漏洞
  261. -->
  262. <dependency>
  263. <groupId>org.quartz-scheduler</groupId>
  264. <artifactId>quartz</artifactId>
  265. <version>2.4.0-rc2</version>
  266. <exclusions>
  267. <exclusion>
  268. <groupId>com.mchange</groupId>
  269. <artifactId>c3p0</artifactId>
  270. </exclusion>
  271. </exclusions>
  272. </dependency>
  273. </dependencies>
  274. </dependencyManagement>
  275. <modules>
  276. <module>ruoyi-admin</module>
  277. <module>ruoyi-framework</module>
  278. <module>ruoyi-system</module>
  279. <module>ruoyi-quartz</module>
  280. <module>ruoyi-postcheck</module>
  281. <module>ruoyi-generator</module>
  282. <module>ruoyi-common</module>
  283. </modules>
  284. <packaging>pom</packaging>
  285. <build>
  286. <plugins>
  287. <plugin>
  288. <groupId>org.apache.maven.plugins</groupId>
  289. <artifactId>maven-compiler-plugin</artifactId>
  290. <version>3.1</version>
  291. <configuration>
  292. <source>${java.version}</source>
  293. <target>${java.version}</target>
  294. <encoding>${project.build.sourceEncoding}</encoding>
  295. </configuration>
  296. </plugin>
  297. </plugins>
  298. </build>
  299. <repositories>
  300. <repository>
  301. <id>public</id>
  302. <name>aliyun nexus</name>
  303. <url>https://maven.aliyun.com/repository/public</url>
  304. <releases>
  305. <enabled>true</enabled>
  306. </releases>
  307. </repository>
  308. </repositories>
  309. <pluginRepositories>
  310. <pluginRepository>
  311. <id>public</id>
  312. <name>aliyun nexus</name>
  313. <url>https://maven.aliyun.com/repository/public</url>
  314. <releases>
  315. <enabled>true</enabled>
  316. </releases>
  317. <snapshots>
  318. <enabled>false</enabled>
  319. </snapshots>
  320. </pluginRepository>
  321. </pluginRepositories>
  322. </project>