This is an automated email from the ASF dual-hosted git repository.

dependabot[bot] pushed a change to branch dependabot/maven/bcprov.version-1.86
in repository https://gitbox.apache.org/repos/asf/ws-wss4j.git


    omit 6cbb15c00 Bump bcprov.version from 1.84 to 1.86
     add 54a293865 Bump org.apache.maven.plugins:maven-jar-plugin from 3.5.0 to 
3.5.1 (#692)
     add ac28affa7 Fix signature replay caching (#699)
     add a07804833 Fix StAX replaycache tests (#703)
     add a2f8e4fff Fix nonce encoding issue (#704)
     add 4d50f228d Bump org.apache:apache from 37 to 39 (#702)
     add b838b11e9 Bump org.apache.maven.plugins:maven-surefire-plugin from 
3.5.6 to 3.6.0 (#701)
     add e2fdad67f Bump org.cyclonedx:cyclonedx-maven-plugin from 2.9.2 to 
2.9.3 (#700)
     add aa028e6af Only set trust validation for Signature when we have a 
trusted source (#705)
     add d2939c88e Adding docs about trust credentials for BST (#706)
     add a52aaee7c Putting max on UsernameToken stax iterations (#707)
     add d6323f3e8 Set trust when there is no KeyInfo and the certificate comes 
from a local keystore (#708)
     add 3ae19b522 Adding some derived key tests
     add 720a401c2 Additional Bleichenbacher fix (#709)
     add 277e55481 Updating Neethi to 3.2.4 (#710)
     add d7d6fb0e2 Javadoc updates
     add 77d665e53 Redact passwords from UsernameToken toString (#711)
     add efbcbfc37 Bound the encrypted data nesting depth (#713)
     add c9cdddace Document streaming policy enforcement (#714)
     add d2a7450e8 Updating threat model with bounds
     add 623bfb888 Stricter policy enforcement (#715)
     add a8fb5fe7a Better document REQUIRE_SIGNED_ENCRYPTED_DATA_ELEMENTS
     add 2a67fc398 Properly wire UsernameToken + RSA15 flags for the streaming 
layer (#717)
     add 240c68a6c Improving kerberos docs
     add 4050df2a0 Fix SenderVouches EncryptedKey case (#718)
     add 4fc06f524 Extend the EncryptedKey random-key fallback beyond 
decryptDataRef (#719)
     add 79cc522f0 More docs updates
     add 204418698 Align StaX sender vouches with DOM layer (#720)
     add d656ae463 Docs update for SAML audience
     add 6b4ebdf34 Fix SAML Conditions parsing (#721)
     add 6de1f273a Revert "Fix SenderVouches EncryptedKey case (#718)"
     add d84b48267 Revert "Align StaX sender vouches with DOM layer (#720)"
     add c7284e74e Bump org.apache.felix:maven-bundle-plugin from 6.1.2 to 
6.2.0 (#716)
     add 11bd6938c Fix timestamp parsing (#722)
     add 9629b626a Update certs that are failing with the Bouncycastle update 
(#723)
     add 81501d28e Bump bcprov.version from 1.84 to 1.86

This update added new revisions after undoing existing revisions.
That is to say, some revisions that were in the old version of the
branch are not in the new version.  This situation occurs
when a user --force pushes a change and generates a repository
containing something like this:

 * -- * -- B -- O -- O -- O   (6cbb15c00)
            \
             N -- N -- N   refs/heads/dependabot/maven/bcprov.version-1.86 
(81501d28e)

You should already have received notification emails for all of the O
revisions, and so the following emails describe only the N revisions
from the common base, B.

Any revisions marked "omit" are not gone; other references still
refer to them.  Any revisions marked "discard" are gone forever.

No new revisions were added by this update.

Summary of changes:
 THREAT-MODEL.md                                    | 239 +++++++++++++++++-
 parent/pom.xml                                     |   4 +-
 pom.xml                                            |   8 +-
 src/site/asciidoc/best_practice.adoc               |  48 ++++
 src/site/asciidoc/config.adoc                      |  14 +-
 src/site/asciidoc/streaming.adoc                   |  31 +++
 .../wss4j/common/ConfigurationConstants.java       |  18 +-
 .../wss4j/common/saml/SamlAssertionWrapper.java    |  17 +-
 .../wss4j/common/util/UsernameTokenUtil.java       |  35 +++
 .../common/crypto/AlgorithmSuiteValidatorTest.java |  72 ++++++
 .../keys/nameconstraints/intermediate_signed.p12   | Bin 4224 -> 4524 bytes
 .../keys/nameconstraints/nameconstraints.jks       | Bin 2204 -> 2200 bytes
 .../resources/keys/nameconstraints/root_signed.p12 | Bin 3569 -> 3741 bytes
 .../org/apache/wss4j/dom/engine/WSSConfig.java     |   9 +
 .../wss4j/dom/engine/WSSecurityEngineResult.java   |   9 +
 .../org/apache/wss4j/dom/handler/RequestData.java  |  41 +++
 .../org/apache/wss4j/dom/message/WSSecDKSign.java  |  14 ++
 .../apache/wss4j/dom/message/token/Timestamp.java  |  22 +-
 .../wss4j/dom/message/token/UsernameToken.java     |  19 +-
 .../dom/processor/EncryptedAssertionProcessor.java |  24 +-
 .../dom/processor/EncryptedDataProcessor.java      |  29 ++-
 .../wss4j/dom/processor/EncryptedKeyProcessor.java |  46 +++-
 .../dom/processor/ReferenceListProcessor.java      |   4 +-
 .../wss4j/dom/processor/SignatureProcessor.java    | 128 ++++++++--
 .../dom/processor/UsernameTokenProcessor.java      |  29 ++-
 .../org/apache/wss4j/dom/str/STRParserResult.java  |  17 ++
 .../wss4j/dom/str/SecurityTokenRefSTRParser.java   |   1 +
 .../wss4j/dom/handler/RequestDataNestingTest.java  | 134 ++++++++++
 .../apache/wss4j/dom/message/DerivedKeyTest.java   | 121 +++++++++
 .../dom/message/EncryptedKeyLengthOracleTest.java  | 279 +++++++++++++++++++++
 .../org/apache/wss4j/dom/message/ReplayTest.java   | 251 ++++++++++++++++++
 .../apache/wss4j/dom/message/SignatureTest.java    |  46 ++++
 .../wss4j/dom/message/SymmetricSignatureTest.java  |  61 ++++-
 .../apache/wss4j/dom/message/TimestampTest.java    |  65 +++++
 .../apache/wss4j/dom/message/UTDerivedKeyTest.java |  40 +++
 .../message/token/UsernameTokenToStringTest.java   | 118 +++++++++
 .../apache/wss4j/dom/saml/SamlConditionsTest.java  | 104 ++++++++
 .../wss4j/dom/saml/SignedSamlTokenHOKTest.java     |   5 +
 .../wss4j/policy/stax/enforcer/PolicyEnforcer.java | 172 +++++++++++--
 .../stax/enforcer/PolicyEnforcerFactory.java       |  82 +++++-
 .../policy/stax/enforcer/PolicyInputProcessor.java |  16 +-
 .../policy/stax/test/ScopedEngineDefaultsTest.java | 155 ++++++++++++
 .../policy/stax/test/VulnerabliltyVectorsTest.java | 129 ++++++++++
 .../testdata/wsdl/mixedPasswordPolicies.wsdl       |  98 ++++++++
 .../test/resources/testdata/wsdl/rpcOperation.wsdl |  64 +++++
 .../processor/input/UsernameTokenInputHandler.java |  30 ++-
 .../WSSSignatureReferenceVerifyInputProcessor.java |  98 ++++++--
 .../securityToken/UsernameSecurityTokenImpl.java   |  15 ++
 .../org/apache/wss4j/stax/test/ReplayTest.java     | 172 +++++++++++++
 .../stax/test/UsernameTokenIterationTest.java      | 156 ++++++++++++
 50 files changed, 3169 insertions(+), 120 deletions(-)
 create mode 100644 
ws-security-dom/src/test/java/org/apache/wss4j/dom/handler/RequestDataNestingTest.java
 create mode 100644 
ws-security-dom/src/test/java/org/apache/wss4j/dom/message/EncryptedKeyLengthOracleTest.java
 create mode 100644 
ws-security-dom/src/test/java/org/apache/wss4j/dom/message/token/UsernameTokenToStringTest.java
 create mode 100644 
ws-security-policy-stax/src/test/java/org/apache/wss4j/policy/stax/test/ScopedEngineDefaultsTest.java
 create mode 100644 
ws-security-policy-stax/src/test/resources/testdata/wsdl/mixedPasswordPolicies.wsdl
 create mode 100644 
ws-security-policy-stax/src/test/resources/testdata/wsdl/rpcOperation.wsdl
 create mode 100644 
ws-security-stax/src/test/java/org/apache/wss4j/stax/test/UsernameTokenIterationTest.java

Reply via email to