Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump SSHJ to 0.26.0 #45

Merged
merged 1 commit into from
Apr 21, 2019
Merged

Bump SSHJ to 0.26.0 #45

merged 1 commit into from
Apr 21, 2019

Conversation

jzt
Copy link
Contributor

@jzt jzt commented Dec 6, 2018

SSHJ 0.23.0 depends on bouncycastle 1.56, which is subject to the following vulnerabilities:

https://nvd.nist.gov/vuln/detail/CVE-2018-1000180
https://nvd.nist.gov/vuln/detail/CVE-2018-1000613

Bumping to 0.26.0 would fix these transitive issues.

SSHJ 0.23.0 depends on bouncycastle 1.56, which is subject to the following vulnerabilities:

https://nvd.nist.gov/vuln/detail/CVE-2018-1000180
https://nvd.nist.gov/vuln/detail/CVE-2018-1000613
https://nvd.nist.gov/vuln/detail/CVE-2018-1000180

Bumping to 0.26.0 would fix these transitive issues.
@xuwei-k xuwei-k merged commit 0211074 into sirthias:master Apr 21, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants