Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

@relaxedboi
Copy link
Contributor

No description provided.

@github-actions github-actions bot added the community-contribution PR or Issue raised by member(s) of DataHub Community label Nov 28, 2025
@datahub-cyborg datahub-cyborg bot added the needs-review Label for PRs that need review from a maintainer. label Nov 28, 2025
@deepgarg760 deepgarg760 self-assigned this Nov 28, 2025
@deepgarg760
Copy link
Collaborator

@relaxedboi , please mention reason for this

@datahub-cyborg datahub-cyborg bot added merge-pending-ci A PR that has passed review and should be merged once CI is green. and removed needs-review Label for PRs that need review from a maintainer. labels Nov 28, 2025
@relaxedboi
Copy link
Contributor Author

@relaxedboi , please mention reason for this

CWE-328: Use of Weak Hash

Bouncy Castle is vulnerable due to the Use of Weak Hash. The createClone() method in the DigestFactory$2.class class does not properly clone SHA-1 hashes. An unsuspected developer can use the vulnerable method to perform cryptographic operations, exposing the application to collision attacks.

@codecov
Copy link

codecov bot commented Nov 28, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

@codecov
Copy link

codecov bot commented Nov 28, 2025

Bundle Report

Bundle size has no change ✅

@deepgarg760 deepgarg760 merged commit d9fc440 into datahub-project:master Dec 1, 2025
33 checks passed
Tim-Visser pushed a commit to Tim-Visser/datahub that referenced this pull request Dec 1, 2025
@relaxedboi relaxedboi deleted the fix/org.bouncycastle-bcprov-jdk18on branch December 2, 2025 14:59
yonglingsong pushed a commit to yonglingsong/datahub that referenced this pull request Dec 2, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

community-contribution PR or Issue raised by member(s) of DataHub Community merge-pending-ci A PR that has passed review and should be merged once CI is green.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants