Story #16471: update droid to 6.9.14 - #121
Merged
Merged
Conversation
|
Fixed Issues (2)Great job! The following issues were fixed in this Pull Request
Use @Checkmarx to take action directly from this PR:
Try it: |
mkhediri
approved these changes
Sep 23, 2026
Regzox
force-pushed
the
story_16471__droid_6_9_upgrade
branch
from
September 23, 2026 14:37
3b3906c to
2b4240a
Compare
Droid 6.8.0 is the last source of known vulnerabilities in the dependency tree: it depends on commons-lang 2.6 (CVE-2025-48924) and commons-configuration 1.10 (CVE-2025-46392), two end-of-life branches with no upstream fix. Droid 6.9.14 moves to commons-lang3 and commons-configuration2, which clears both. No source change is needed: the droid API sedalib relies on is unchanged, and the DROID_SignatureFile / container-signature resources are runtime data independent of the droid version. Two side effects of the bump are handled in sedalib: - jwat-common 1.2.1 brings bcprov-jdk15to18 1.65, another end-of-life bouncycastle branch carrying eleven CVEs including one critical. It is excluded, like bcprov-jdk15on already was, in favour of bcprov-jdk18on. - droid-core-interfaces 6.9 added S3 profile support, dragging in the AWS SDK v2 and, through netty-nio-client, netty. It declares eight artifacts of the software.amazon.awssdk group, so the whole group is excluded: excluding s3 alone still left netty 4.1.137.Final reachable through sso, carrying seven high-severity CVEs. Sedatools only identifies files on the local filesystem, so none of it is used. This brings the resip shaded jar down from 84.1 MB to 68.7 MB. Droid 6.9 ships class file version 65, so this cannot be merged before the Java 21 migration. It also builds on the bouncycastle pin and the bcprov-jdk18on replacement introduced by the dependency update.
Regzox
force-pushed
the
story_16471__droid_6_9_upgrade
branch
from
September 23, 2026 14:48
2b4240a to
efaeef8
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


No description provided.