apache / linkis

Apache Linkis builds a computation middleware layer to facilitate connection, governance and orchestration between the upper applications and the underlying data engines.
https://linkis.apache.org/
Apache License 2.0
3.31k stars 1.17k forks source link

[Bug] switch to bcprov-jdk18on jar because the jdk15on one is not maintained and has security issues #5179

Closed pjfanning closed 1 week ago

pjfanning commented 1 month ago

Search before asking

Linkis Component

linkis-commons

Steps to reproduce

https://www.bouncycastle.org/download/bouncy-castle-java/#release-notes

CVES like https://github.com/apache/linkis/security/dependabot/111

Expected behavior

use secure jars

Your environment

Anything else

No response

Are you willing to submit a PR?

github-actions[bot] commented 1 month ago

:blush: Welcome to the Apache Linkis community!!

We are glad that you are contributing by opening this issue.

Please make sure to include all the relevant context. We will be here shortly.

If you are interested in contributing to our website project, please let us know! You can check out our contributing guide on :point_right: How to Participate in Project Contribution.

Community

WeChat Assistant WeChat Public Account

Mailing Lists

Name Description Subscribe Unsubscribe Archive
dev@linkis.apache.org community activity information subscribe unsubscribe archive