Skip to content

Conversation

@lhotari
Copy link
Member

@lhotari lhotari commented Oct 30, 2024

Motivation

OWASP dependency check shows an error for bcprov-jdk15-on dependency.

One or more dependencies were identified with known vulnerabilities in Apache Pulsar :: Tiered Storage :: Parent:

bcprov-jdk15on-1.70.jar (pkg:maven/org.bouncycastle/bcprov-jdk15on@1.70, cpe:2.3:a:bouncycastle:bouncy-castle-crypto-package:1.70:*:*:*:*:*:*:*, cpe:2.3:a:bouncycastle:bouncy_castle_crypto_package:1.70:*:*:*:*:*:*:*, cpe:2.3:a:bouncycastle:bouncy_castle_for_java:1.70:*:*:*:*:*:*:*, cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.70:*:*:*:*:*:*:*, cpe:2.3:a:bouncycastle:the_bouncy_castle_crypto_package_for_java:1.70:*:*:*:*:*:*:*) : CVE-2024-34447, CVE-2024-29857, CVE-2024-30171, CVE-2023-33202, CVE-2023-33201

Modifications

Replace outdated bcprov-jdk15-on dependency with bcprov-jdk18-on which continues to be updated.

Documentation

  • doc
  • doc-required
  • doc-not-needed
  • doc-complete

@lhotari lhotari added this to the 4.1.0 milestone Oct 30, 2024
@lhotari lhotari self-assigned this Oct 30, 2024
@github-actions github-actions bot added the doc-not-needed Your PR changes do not impact docs label Oct 30, 2024
@codecov-commenter
Copy link

codecov-commenter commented Oct 31, 2024

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 74.32%. Comparing base (bbc6224) to head (bb2dad1).
⚠️ Report is 1496 commits behind head on master.

Additional details and impacted files

Impacted file tree graph

@@             Coverage Diff              @@
##             master   #23532      +/-   ##
============================================
+ Coverage     73.57%   74.32%   +0.74%     
- Complexity    32624    34419    +1795     
============================================
  Files          1877     1943      +66     
  Lines        139502   147045    +7543     
  Branches      15299    16205     +906     
============================================
+ Hits         102638   109284    +6646     
- Misses        28908    29318     +410     
- Partials       7956     8443     +487     
Flag Coverage Δ
inttests 27.62% <ø> (+3.03%) ⬆️
systests 24.36% <ø> (+0.04%) ⬆️
unittests 73.69% <ø> (+0.85%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.
see 653 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants