Skip to content

Commit 52f4b20

Browse files
committed
fix: upgrade bouncy castle dependency to address security vulnerability CVE-2025-8916
- Upgraded com.ibm.mq:com.ibm.mq.allclient from 9.4.0.5 to 9.4.4.1 - This resolves CVE-2025-8916 in org.bouncycastle:bcprov-jdk18on - Bouncy Castle upgraded from 1.78.1 (vulnerable) to 1.81 (fixed) - All unit tests pass successfully - Updated MQ_IMAGE from 9.4.0.5-r2 to 9.4.4.1-r1 in AbstractJMSContextIT - Ensures integration tests run against matching MQ server version Signed-off-by: Meenu Mariya <meenu.mariya@ibm.com>
1 parent 4ed7f64 commit 52f4b20

2 files changed

Lines changed: 2 additions & 2 deletions

File tree

pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@
6363
<dependency>
6464
<groupId>com.ibm.mq</groupId>
6565
<artifactId>com.ibm.mq.allclient</artifactId>
66-
<version>9.4.0.5</version>
66+
<version>9.4.4.1</version>
6767
</dependency>
6868

6969
<dependency>

src/integration/java/com/ibm/eventstreams/connect/mqsink/AbstractJMSContextIT.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -91,7 +91,7 @@ public abstract class AbstractJMSContextIT {
9191
public static final String CONNECTION_MODE = "client";
9292
public static final String HOST_NAME = "localhost";
9393

94-
public static final String MQ_IMAGE = "icr.io/ibm-messaging/mq:9.4.0.5-r2";
94+
public static final String MQ_IMAGE = "icr.io/ibm-messaging/mq:9.4.4.1-r1";
9595
public static final boolean USER_AUTHENTICATION_MQCSP = false;
9696

9797
protected final ObjectMapper mapper = new ObjectMapper();

0 commit comments

Comments
 (0)