Skip to content

[SECURITY] upgrade to bcpkix-jdk18on 1.81 due to CVEs#618

Open
pjfanning wants to merge 1 commit intovesoft-inc:masterfrom
pjfanning:patch-1
Open

[SECURITY] upgrade to bcpkix-jdk18on 1.81 due to CVEs#618
pjfanning wants to merge 1 commit intovesoft-inc:masterfrom
pjfanning:patch-1

Conversation

@pjfanning
Copy link

What type of PR is this?

  • bug
  • feature
  • enhancement

What problem(s) does this PR solve?

Issue(s) number:

Description:

BouncyCastle no longer ship jdk15on jars. Projects should use the jdk18on ones instead.
The jdk15on jars were for Java 1.5 users and fixes that have been made to the jdk18on jars (Java 1.8 compatible) have not been backported - including security fixes.

The last Hertzbeat RC had bcprov-jdk15on-1.69.jar

How do you solve it?

Special notes for your reviewer, ex. impact of this fix, design document, etc:

@CLAassistant
Copy link

CLAassistant commented Jul 5, 2025

CLA assistant check
All committers have signed the CLA.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants