Skip to content

Commit ca2ca2b

Browse files
K2GO-358 fix(deps): raise transitive dep versions
Constrain bcprov-jdk15to18 to 1.85 and okio to 1.17.6 (transitive via libadb-android), and bump commons-io to 2.14.0. Clears Snyk CVEs. Version-only bumps with no direct API use, so app behavior is unchanged.
1 parent 7754a20 commit ca2ca2b

2 files changed

Lines changed: 12 additions & 1 deletion

File tree

‎controller/app/build.gradle‎

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -237,6 +237,17 @@ android {
237237
}
238238

239239
dependencies {
240+
// Security (Snyk): raise vulnerable transitive versions. The app does not call these
241+
// APIs directly, so this changes only the resolved version, not app behavior.
242+
constraints {
243+
implementation('org.bouncycastle:bcprov-jdk15to18:1.85') {
244+
because 'Snyk CVE fixes; pulled transitively by libadb-android 3.1.1 (was 1.81).'
245+
}
246+
implementation('com.squareup.okio:okio:1.17.6') {
247+
because 'Snyk CVE fix; transitive (was 1.17.5).'
248+
}
249+
}
250+
240251
// ADFA-4533: GlitchTip (Sentry-compatible) crash reporting SDK.
241252
implementation 'io.sentry:sentry-android-core:8.29.0'
242253

‎controller/termux-core/build.gradle‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -119,7 +119,7 @@ dependencies {
119119

120120
// --- TERMUX PATCHES ---
121121
implementation 'com.google.guava:guava:31.1-jre'
122-
implementation 'commons-io:commons-io:2.11.0'
122+
implementation 'commons-io:commons-io:2.14.0' // Snyk CVE fix (was 2.11.0)
123123

124124
// Markdown
125125
implementation 'io.noties.markwon:core:4.6.2'

0 commit comments

Comments
 (0)