Job 'Scan Vulnerabilities' failed on 'refs/heads/main' #3127
Robin Shen opened 4 days ago

Build #8475 (reference: OD-8475) of job "Scan Vulnerabilities" on refs/heads/main has failed.

Project: onedev/server Commit: af7eac1e Submitted by: onedev (Scheduled) Submitted at: 2026-09-20T00:59:43.480+00:00 Pending duration: 153880 ms Running duration: 236958 ms Finished at: 2026-09-20T01:06:14.373+00:00

Build link: https://code.onedev.io/onedev/server/~builds/8475

  • Robin Shen changed fields 4 days ago
    Name Previous Value Current Value
    Assignee
    servicedesk
    wh
  • Work Horse referenced from pull request 4 days ago
  • Work Horse commented 4 days ago

    Build OD-8475 failed on CVE-2026-8763 (critical) and CVE-2026-13506 (high) in Bouncy Castle 1.84; the report identifies 1.85 as fixing both. Updated the shared Bouncy Castle version to 1.85, keeping all five libraries aligned.

    Validation: mvn -pl server-product -am -Dmaven.test.skip=true -Dmaven.source.skip=true package passed for the full product reactor. Confirmed the packaged distribution contains only the five Bouncy Castle 1.85 jars. Tests were skipped, and Trivy is unavailable locally, so the vulnerability scan requires CI verification.

    Submitted as PR #124.

  • OneDev commented 4 days ago

    State changed as pull request OD-124 is merged

  • OneDev changed state to 'Closed' 4 days ago
    Previous Value Current Value
    Open
    Closed
1/1
Type
Build Failed
Priority
Major
Assignee
Labels
No labels
Build
Not Found
Issue Votes (0)
Watchers (3)
Reference
OD-3127
Please wait...
Connection lost or session expired, reload to recover
Page is in error, reload to recover