Skip to content

Conversation

@lhotari
Copy link
Member

@lhotari lhotari commented Aug 20, 2025

Motivation & Modifications

Upgrade bouncycastle version to 1.79 to address CVE-2025-8916.

Since all bouncycastle libraries don't have aligned version numbers, the pom.xml has been modified so that different versions can be specified.

This CVE also applies to the org.bouncycastle:bcpkix-fips dependency, but there's no 1.0.8 version available yet. That will be upgraded in another PR when the fix is available.

Documentation

  • doc
  • doc-required
  • doc-not-needed
  • doc-complete

@lhotari lhotari force-pushed the lh-upgrade-bouncycastle-1.79 branch from e410715 to 99ecb7d Compare August 20, 2025 13:19
@lhotari lhotari changed the title [fix][sec] Upgrade bouncycastle version to 1.79 to address CVE-2025-8916 [fix][sec] Upgrade bouncycastle bcpkix-fips version to 1.79 to address CVE-2025-8916 Aug 20, 2025
@codecov-commenter
Copy link

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 74.32%. Comparing base (34f8657) to head (99ecb7d).
⚠️ Report is 1 commits behind head on master.

Additional details and impacted files

Impacted file tree graph

@@             Coverage Diff              @@
##             master   #24650      +/-   ##
============================================
- Coverage     74.32%   74.32%   -0.01%     
+ Complexity    33180    33177       -3     
============================================
  Files          1882     1882              
  Lines        146855   146855              
  Branches      16867    16867              
============================================
- Hits         109152   109145       -7     
  Misses        29038    29038              
- Partials       8665     8672       +7     
Flag Coverage Δ
inttests 26.60% <ø> (-0.18%) ⬇️
systests 23.25% <ø> (-0.19%) ⬇️
unittests 73.81% <ø> (+<0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.
see 87 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@lhotari lhotari merged commit e78068a into apache:master Aug 20, 2025
54 checks passed
lhotari added a commit that referenced this pull request Aug 26, 2025
manas-ctds pushed a commit to datastax/pulsar that referenced this pull request Aug 26, 2025
manas-ctds pushed a commit to datastax/pulsar that referenced this pull request Aug 26, 2025
lhotari added a commit that referenced this pull request Aug 26, 2025
nodece pushed a commit to ascentstream/pulsar that referenced this pull request Aug 26, 2025
srinath-ctds pushed a commit to datastax/pulsar that referenced this pull request Aug 28, 2025
ganesh-ctds pushed a commit to datastax/pulsar that referenced this pull request Aug 29, 2025
srinath-ctds pushed a commit to datastax/pulsar that referenced this pull request Sep 3, 2025
catmsred added a commit to catmsred/os that referenced this pull request Oct 21, 2025
bcpkix-jdk18on is brought in my pulsar.  Upstream pulsar fixes this CVE [1], so
bumping pulsar to the version that contains the fix.

[1] apache/pulsar#24650

Relates: chainguard-dev/CVE-Dashboard#31498
catmsred added a commit to catmsred/os that referenced this pull request Oct 21, 2025
bcpkix-jdk18on is brought in my pulsar.  Upstream pulsar fixes this CVE [1], so
bumping pulsar to the version that contains the fix.

[1] apache/pulsar#24650

Relates: chainguard-dev/CVE-Dashboard#31498
catmsred added a commit to catmsred/os that referenced this pull request Oct 21, 2025
bcpkix-jdk18on is brought in my pulsar.  Upstream pulsar fixes this CVE [1], so
bumping pulsar to the version that contains the fix.

[1] apache/pulsar#24650

Relates: chainguard-dev/CVE-Dashboard#31498
powersj pushed a commit to wolfi-dev/os that referenced this pull request Oct 22, 2025
bcpkix-jdk18on is brought in my pulsar. Upstream pulsar fixes this CVE
[1], so
bumping pulsar to the version that contains the fix.

[1] apache/pulsar#24650

Relates: chainguard-dev/CVE-Dashboard#31498

<!--ci-cve-scan:must-fix: GHSA-4cx2-fc23-5wg6-->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants