You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
JRuby does not shade BC. BC is part of jruby-openssl thus you should update the gem (latest uses 1.56 already). there likely wont be more 1.7 releases thus this should be the preferred option.
Release 1.56 of BC fixes 10 different vulnerabilities which all have CVEs.
https://www.bouncycastle.org/releasenotes.html
Threat varies from 3.0 to 7.5 being the highest according to Sonatype.
JRuby 1.7.27 shades the bouncycastle library (v1.55), so it is hard to override with a newer version.
The text was updated successfully, but these errors were encountered: