Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bouncy castle crypto provider vs critical vulnerability. #5572

Merged
merged 1 commit into from Apr 8, 2020

Conversation

skjolber
Copy link
Contributor

@skjolber skjolber commented Apr 8, 2020

Overview

The Bouncy castle provider as its flagged by security scanners because of https://nvd.nist.gov/vuln/detail/CVE-2018-1000613. It is showing up in security scanners, failing builds.

Proposed Changes

Bump to unaffected version.

@skjolber skjolber changed the title Bump bouncy castle provider vs critical vulnerability. Bouncy castle crypto provider vs critical vulnerability. Apr 8, 2020
@hoisie
Copy link
Contributor

hoisie commented Apr 8, 2020

Thanks for fixing this.

@hoisie hoisie merged commit ba6d0fb into robolectric:master Apr 8, 2020
@skjolber skjolber deleted the bouncyCastleUpdate branch April 8, 2020 16:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants