Re: [PR] [fix][sec] Upgrade org.bouncycastle:bc-fips to 1.0.2.4 [pulsar]

2023-12-15 Thread via GitHub
merlimat merged PR #21730: URL: https://github.com/apache/pulsar/pull/21730 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: commits-unsubscr...@pulsar.a

[PR] [fix][sec] Upgrade org.bouncycastle:bc-fips to 1.0.2.4 [pulsar]

2023-12-14 Thread via GitHub
massakam opened a new pull request, #21730: URL: https://github.com/apache/pulsar/pull/21730 ### Motivation The currently used version of `org.bouncycastle:bc-fips` has the following vulnerability and should be upgraded to 1.0.2.4. https://github.com/bcgit/bc-java/wiki/CVE-2022-451