Skip to content

[Snyk] Security upgrade org.bouncycastle:bcprov-jdk15on from 1.66 to 1.67#8

Closed
snyk-bot wants to merge 1 commit intomasterfrom
snyk-fix-1522442f373d3efee19f31b28a134a58
Closed

[Snyk] Security upgrade org.bouncycastle:bcprov-jdk15on from 1.66 to 1.67#8
snyk-bot wants to merge 1 commit intomasterfrom
snyk-fix-1522442f373d3efee19f31b28a134a58

Conversation

@snyk-bot
Copy link
Copy Markdown
Contributor

Snyk has created this PR to fix one or more vulnerable packages in the `maven` dependencies of this project.

✨ Snyk has automatically assigned this pull request, set who gets assigned.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • pom.xml

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Upgrade Breaking Change Exploit Maturity
high severity 651/1000
Why? Recently disclosed, Has a fix available, CVSS 7.3
Comparison Using Wrong Factors
SNYK-JAVA-ORGBOUNCYCASTLE-1052448
org.bouncycastle:bcprov-jdk15on:
1.66 -> 1.67
No No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

👩‍💻 Set who automatically gets assigned

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

@ecki ecki added the dependencies Pull requests that update a dependency file label Jan 29, 2022
@ecki ecki closed this Jan 29, 2022
@ecki ecki deleted the snyk-fix-1522442f373d3efee19f31b28a134a58 branch January 29, 2022 00:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants