Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AJ-1485 update bouncy castle for dependabot alert #1248

Merged
merged 4 commits into from
Nov 29, 2023

Conversation

calypsomatic
Copy link
Contributor

@calypsomatic calypsomatic commented Nov 28, 2023

https://broadworkbench.atlassian.net/browse/AJ-1485
Dependabot alert identified bouncy castle as a vulnerability. Bouncy castle was pulled in through workbench-libs/google2, but updating workbench-libs is out of scope for a reasonable time frame to fix this vulnerability, so this PR updates the transitive dependency directly. See https://broadworkbench.atlassian.net/browse/AJ-1490 for follow-on work to update workbench-libs.

@calypsomatic calypsomatic changed the title Bouncy castle dependabot AJ-1485 update bouncy castle for dependabot alert Nov 29, 2023
Copy link

codecov bot commented Nov 29, 2023

Codecov Report

All modified and coverable lines are covered by tests ✅

Comparison is base (873f123) 69.94% compared to head (ee1d50c) 69.94%.

Additional details and impacted files
@@           Coverage Diff            @@
##           develop    #1248   +/-   ##
========================================
  Coverage    69.94%   69.94%           
========================================
  Files          101      101           
  Lines         3500     3500           
  Branches       371      371           
========================================
  Hits          2448     2448           
  Misses        1052     1052           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@calypsomatic calypsomatic marked this pull request as ready for review November 29, 2023 14:49
@calypsomatic calypsomatic merged commit 7ba2b5d into develop Nov 29, 2023
7 checks passed
@calypsomatic calypsomatic deleted the bouncy-castle-dependabot branch November 29, 2023 15:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants