Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Provides transitive vulnerable dependency org.bouncycastle:bcprov-jdk15on:1.67 Vulnerability with high severity found #103

Closed
leshalv opened this issue May 1, 2022 · 5 comments

Comments

@leshalv
Copy link

leshalv commented May 1, 2022

https://advisory.checkmarx.net/advisory/vulnerability/Cxa9261daf-3755/

@Dzkol Dzkol closed this as completed Feb 19, 2024
@leshalv
Copy link
Author

leshalv commented Feb 19, 2024

怎么给关闭了呀 @Jeffreykzli

@leshalv
Copy link
Author

leshalv commented Feb 19, 2024

bcprov-jdk15on:1.67 这个依赖有漏洞,需要处理一下的

@leshalv
Copy link
Author

leshalv commented Feb 19, 2024

咱们SDK最低支持jdk18,为什么不将bcprov提升为jdk18on?

@leshalv
Copy link
Author

leshalv commented Feb 19, 2024

image

@Dzkol
Copy link
Collaborator

Dzkol commented Feb 19, 2024

我们会排期安排升级依赖哈,已经录了需求单,待后续排期、升级、测试没问题之后,会安排发布

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants