Skip to content

Conversation

@ChengDaqi2023
Copy link

What happened?

There are 1 security vulnerabilities found in org.bouncycastle:bc-fips 1.0.2.3

What did I do?

Upgrade org.bouncycastle:bc-fips from 1.0.2.3 to for vulnerability fix

What did you expect to happen?

Ideally, no insecure libs should be used.

The specification of the pull request

PR Specification from OSCS

@github-actions
Copy link

github-actions bot commented Aug 9, 2023

@ChengDaqi2023 Please add the following content to your PR description and select a checkbox:

- [ ] `doc` <!-- Your PR contains doc changes -->
- [ ] `doc-required` <!-- Your PR changes impact docs and you will update later -->
- [ ] `doc-not-needed` <!-- Your PR changes do not impact docs -->
- [ ] `doc-complete` <!-- Docs have been already added -->

@coderzc
Copy link
Member

coderzc commented Aug 10, 2023

@ChengDaqi2023 Please also update LICENSE.bin.txt

@tisonkun tisonkun changed the title fix(sec): upgrade org.bouncycastle:bc-fips to [fix][sec] upgrade org.bouncycastle:bc-fips to Aug 23, 2023
@tisonkun tisonkun changed the title [fix][sec] upgrade org.bouncycastle:bc-fips to [fix][sec] Upgrade org.bouncycastle:bc-fips to 1.0.2.4 Aug 23, 2023
@tisonkun
Copy link
Member

tisonkun commented Aug 23, 2023

Could not resolve dependencies for project org.apache.pulsar:pulsar-common:jar:3.1.0-SNAPSHOT: Could not find artifact org.bouncycastle:bc-fips:jar:1.0.2.4 in central

IIRC this version has been yet release - bcgit/bc-java#1371

@tisonkun tisonkun closed this Aug 23, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants