[ 
https://issues.apache.org/jira/browse/CASSANDRA-19739?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17861283#comment-17861283
 ] 

Francisco Guerrero commented on CASSANDRA-19739:
------------------------------------------------

One thing I noticed was that bouncy castle was only used for tests. Looking at 
CASSANDRA-17992, it looks like the purpose was specifically to bring those deps 
for testing purposes. I think we should change the scope of bouncy castle deps 
to {{test}}.

> Investigate bcprov-jdk18on-1.76.jar: CVE-2024-30172, CVE-2024-30171, 
> CVE-2024-29857, CVE-2024-34447
> ---------------------------------------------------------------------------------------------------
>
>                 Key: CASSANDRA-19739
>                 URL: https://issues.apache.org/jira/browse/CASSANDRA-19739
>             Project: Cassandra
>          Issue Type: Task
>          Components: Build
>            Reporter: Stefan Miklosovic
>            Assignee: Stefan Miklosovic
>            Priority: Normal
>             Fix For: 5.0-rc, 5.x
>
>
> This came up after I bumped dependency-check version to 10.0.0 as suggested 
> in CASSANDRA-19738.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: commits-unsubscr...@cassandra.apache.org
For additional commands, e-mail: commits-h...@cassandra.apache.org

Reply via email to