Skip to content

Commit 4247cd3

Browse files
authored
Pin bouncycastle to 1.84 to fix CVE-2026-0636, CVE-2026-5588, CVE-2026-5598 (open-telemetry#2783)
1 parent cb3ab8e commit 4247cd3

2 files changed

Lines changed: 4 additions & 2 deletions

File tree

dependencyManagement/build.gradle.kts

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -50,6 +50,8 @@ dependencies {
5050
api("org.assertj:assertj-core:3.27.7")
5151
api("org.awaitility:awaitility:4.3.0")
5252
api("org.bouncycastle:bcpkix-jdk15on:1.70")
53+
api("org.bouncycastle:bcpkix-jdk18on:1.84")
54+
api("org.bouncycastle:bcprov-jdk18on:1.84")
5355
api("org.junit-pioneer:junit-pioneer:1.9.1")
5456
api("org.skyscreamer:jsonassert:1.5.3")
5557
api("org.apache.kafka:kafka-clients:4.2.0")

jmx-scraper/build.gradle.kts

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -39,8 +39,8 @@ testing {
3939
implementation("com.linecorp.armeria:armeria-junit5")
4040
implementation("com.linecorp.armeria:armeria-grpc")
4141
implementation("io.opentelemetry.proto:opentelemetry-proto:1.10.0-alpha")
42-
implementation("org.bouncycastle:bcprov-jdk18on:1.84")
43-
implementation("org.bouncycastle:bcpkix-jdk18on:1.84")
42+
implementation("org.bouncycastle:bcprov-jdk18on")
43+
implementation("org.bouncycastle:bcpkix-jdk18on")
4444
}
4545
}
4646
}

0 commit comments

Comments
 (0)