Skip to content

[RUN-4336] Update for CVEs including Bouncy Castle 1.84#96

Open
fdevans wants to merge 1 commit intomainfrom
RUN-4336
Open

[RUN-4336] Update for CVEs including Bouncy Castle 1.84#96
fdevans wants to merge 1 commit intomainfrom
RUN-4336

Conversation

@fdevans
Copy link
Copy Markdown
Contributor

@fdevans fdevans commented Apr 29, 2026

No description provided.

Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates dependency versions to address CVEs (notably upgrading Bouncy Castle), and aligns the plugin’s published metadata with the intended Rundeck compatibility.

Changes:

  • Bump Gradle version-catalog entries including Bouncy Castle to 1.84 (plus Groovy, Objenesis, and Axion Release plugin).
  • Update the rundeck-cli container’s npm overrides/lockfile to use axios 1.15.2 (and updated transitive follow-redirects).
  • Adjust plugin manifest attributes to declare Rundeck 6.x+ compatibility and update the author string.

Reviewed changes

Copilot reviewed 2 out of 4 changed files in this pull request and generated no comments.

File Description
gradle/libs.versions.toml Updates centralized dependency/plugin versions (incl. Bouncy Castle 1.84).
docker/client/rundeck-cli/package.json Bumps axios override to a patched version.
docker/client/rundeck-cli/package-lock.json Regenerates lock entries to match updated axios (and transitive follow-redirects).
build.gradle Updates plugin manifest metadata for Rundeck compatibility and author.
Files not reviewed (1)
  • docker/client/rundeck-cli/package-lock.json: Language not supported

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants