Skip to content

Conversation

@fdevans
Copy link
Contributor

@fdevans fdevans commented Nov 24, 2025

Summary:
CVE-2025-8916 affects Bouncy Castle versions 1.44-1.78 (fixed in 1.79)
✅ SSHJ 0.40.0 includes the updated Bouncy Castle dependency (fixed)
✅ All required dependencies verified (eddsa, bouncycastle bundles)
✅ Build successful - all tests passed

Closes #79

Copilot AI review requested due to automatic review settings November 24, 2025 23:00
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This pull request updates the SSHJ library from version 0.39.0 to 0.40.0 to address CVE-2025-8916, a security vulnerability affecting Bouncy Castle versions 1.44-1.78. The update ensures the project uses SSHJ 0.40.0, which includes the fixed Bouncy Castle dependency (version 1.79+). The project already has Bouncy Castle 1.80 configured, which is compatible with the updated SSHJ version.

Key Changes

  • Updated SSHJ dependency from 0.39.0 to 0.40.0 in the Gradle version catalog
  • Ensures CVE-2025-8916 vulnerability is mitigated through updated transitive Bouncy Castle dependencies
  • All tests passed successfully according to the PR description

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

You can also share your feedback on Copilot code review for a chance to win a $100 gift card. Take the survey.

@fdevans fdevans requested a review from a team November 25, 2025 16:19
@ronaveva ronaveva self-requested a review December 2, 2025 17:19
Copy link
Contributor

@ronaveva ronaveva left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@ronaveva ronaveva merged commit b3cff17 into main Dec 2, 2025
1 of 2 checks passed
@ronaveva ronaveva deleted the RUN-3894 branch December 2, 2025 19:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants