Skip to content

[Snyk] Upgrade org.bouncycastle:bcprov-jdk18on from 1.84 to 1.85 - #34

Open
martin-lindstrom wants to merge 1 commit into
masterfrom
snyk-upgrade-8b3a7c7799c9f7360d16a617c955c0bd
Open

[Snyk] Upgrade org.bouncycastle:bcprov-jdk18on from 1.84 to 1.85#34
martin-lindstrom wants to merge 1 commit into
masterfrom
snyk-upgrade-8b3a7c7799c9f7360d16a617c955c0bd

Conversation

@martin-lindstrom

Copy link
Copy Markdown
Member

snyk-top-banner

Snyk has created this PR to upgrade org.bouncycastle:bcprov-jdk18on from 1.84 to 1.85.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 1 version ahead of your current version.

  • The recommended version was released 22 days ago.

Breaking Change Risk

Merge Risk: Medium

Notice: This assessment is enhanced by AI.


Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade org.bouncycastle:bcprov-jdk18on from 1.84 to 1.85.

See this package in maven:
org.bouncycastle:bcprov-jdk18on

See this project in Snyk:
https://app.snyk.io/org/sunet/project/502fb42b-2166-4b57-8ebb-5db9c9ef8dfd?utm_source=github&utm_medium=referral&page=upgrade-pr
@martin-lindstrom

Copy link
Copy Markdown
Member Author

Merge Risk: Medium

This is a minor, security-focused upgrade from version 1.84 to 1.85. While no mandatory API removals are documented, the release notes describe it as a "significant hardening of the APIs" as a result of advanced code analysis. [1]

Key Changes:

  • API Hardening: This may introduce stricter validation or minor behavioral changes. Code that previously worked with more lenient inputs might now fail. Verification is recommended.
  • Security Fixes: The release addresses multiple CVEs, and the Bouncy Castle team strongly encourages users to update. [2, 9]
  • New Features: The release adds significant new functionality, including expanded Post-Quantum Cryptography (PQC) support, a new high-level CAdES API for electronic signatures, and modernized CMS capabilities. These changes are primarily additive. [1]

Recommendation:
Given the API hardening, it is important to perform regression testing after the upgrade to ensure that existing cryptographic operations behave as expected. Pay close attention to areas where your application might be passing ambiguous or non-standard data.

Source: Bouncy Castle 1.85 Release Announcement [1]

Notice 🤖: This content was augmented using artificial intelligence. AI-generated content may contain errors and should be reviewed for accuracy before use.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants