flyingsaucerproject / flyingsaucer

XML/XHTML and CSS 2.1 renderer in pure Java
Other
2.01k stars 559 forks source link

upgrade bouncycastle to 1.70 #180

Closed urld closed 1 year ago

urld commented 2 years ago

CVE-2020-15522 in bcprov 1.64 looks bad on depency-check report when using flying-saucer-pdf-osgi

urld commented 1 year ago

Thx for merging @pbrant . However, i think bcprov 1.70 has been outdated again for a while now. You may want to check the latest version. I think that would be 1.76.

pbrant commented 1 year ago

Thanks. I've updated to 1.76.

On Mon, Sep 4, 2023 at 5:16 PM David Url @.***> wrote:

Thx for merging this. However, i think bcprov 1.70 has been outdated again for a while now. You may want to check the latest version. I think that would be 1.76.

— Reply to this email directly, view it on GitHub https://github.com/flyingsaucerproject/flyingsaucer/pull/180#issuecomment-1705434684, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAAF42F5KAQIOPDXRRHLDSDXYXWGLANCNFSM5UF6LCKQ . You are receiving this because you modified the open/close state.Message ID: @.***>

pbrant commented 1 year ago

Released 9.2.0