oci-java-sdk icon indicating copy to clipboard operation
oci-java-sdk copied to clipboard

Update pom.xml

Open isinghabhishek opened this issue 2 years ago • 3 comments

Updating the latest version of Bouncy Castle is 1.74 which was released on Monday 12th June 2023.

isinghabhishek avatar Jul 03 '23 09:07 isinghabhishek

Thank you for your pull request and welcome to our community! To contribute, please sign the Oracle Contributor Agreement (OCA). The following contributors of this PR have not signed the OCA:

To sign the OCA, please create an Oracle account and sign the OCA in Oracle's Contributor Agreement Application.

When signing the OCA, please provide your GitHub username. After signing the OCA and getting an OCA approval from Oracle, this PR will be automatically updated.

If you are an Oracle employee, please make sure that you are a member of the main Oracle GitHub organization, and your membership in this organization is public.

@isinghabhishek, is this update in response to a CVE? Can you elaborate on why this is required? thanks!

joshunter avatar Jul 05 '23 23:07 joshunter

I see this is related to https://github.com/bcgit/bc-java/wiki/CVE-2023-33201. I'll look into bumping this version. Thanks @isinghabhishek !

joshunter avatar Jul 07 '23 21:07 joshunter