-
Name Previous Value Current Value Assignee
servicedesk
wh
-
-
Build OD-8475 failed on CVE-2026-8763 (critical) and CVE-2026-13506 (high) in Bouncy Castle 1.84; the report identifies 1.85 as fixing both. Updated the shared Bouncy Castle version to 1.85, keeping all five libraries aligned.
Validation:
mvn -pl server-product -am -Dmaven.test.skip=true -Dmaven.source.skip=true packagepassed for the full product reactor. Confirmed the packaged distribution contains only the five Bouncy Castle 1.85 jars. Tests were skipped, and Trivy is unavailable locally, so the vulnerability scan requires CI verification.Submitted as PR #124.
-
State changed as pull request OD-124 is merged
-
OneDev
changed state to 'Closed' 4 days ago
Previous Value Current Value Open
Closed
| Type |
Build Failed
|
| Priority |
Major
|
| Assignee | |
| Labels |
No labels
|
| Build |
Not Found
|
Issue Votes (0)
Build #8475 (reference: OD-8475) of job "Scan Vulnerabilities" on refs/heads/main has failed.
Project: onedev/server Commit: af7eac1e Submitted by: onedev (Scheduled) Submitted at: 2026-09-20T00:59:43.480+00:00 Pending duration: 153880 ms Running duration: 236958 ms Finished at: 2026-09-20T01:06:14.373+00:00
Build link: https://code.onedev.io/onedev/server/~builds/8475