Bump the dependencies group across 1 directory with 15 updates #2438

Open
dependabot[bot] opened 11:38am on September 21, 2026 wants to merge 1 commit into fraunhoferiosb/frost-server v2.8.x from
dependabot/maven/v2.8.x/dependencies-60b0c7f7d0
Diff Delta:
0
Classified as:  General

dependabot-bot's Description of Work

Bumps the dependencies group with 15 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| de.fraunhofer.iosb.ilt:FROST-Client-Dynamic | 2.38 | 2.39 |
| io.prometheus:prometheus-metrics-bom | 1.8.0 | 1.9.0 |
| org.eclipse.jetty.ee10:jetty-ee10-servlet | 12.1.12 | 12.1.13 |
| org.jooq:jooq | 3.21.7 | 3.21.8 |
| org.jooq:jooq-codegen | 3.21.7 | 3.21.8 |
| org.jooq:jooq-meta | 3.21.7 | 3.21.8 |
| org.jooq:jooq-codegen | 3.21.7 | 3.21.8 |
| org.jooq:jooq-meta | 3.21.7 | 3.21.8 |
| org.slf4j:jul-to-slf4j | 2.0.18 | 2.0.19 |
| org.slf4j:slf4j-api | 2.0.18 | 2.0.19 |
| org.slf4j:slf4j-api | 2.0.18 | 2.0.19 |
| org.codehaus.mojo:build-helper-maven-plugin | 3.6.1 | 3.6.2 |
| org.codehaus.mojo:exec-maven-plugin | 3.6.3 | 3.6.4 |
| org.sonarsource.scanner.maven:sonar-maven-plugin | 5.7.0.6970 | 5.8.0.7211 |
| com.diffplug.spotless:spotless-maven-plugin | 3.10.1 | 3.10.2 |
| org.bouncycastle:bcpkix-jdk18on | 1.85 | 1.86 |
| org.bouncycastle:bcprov-jdk18on | 1.85 | 1.86 |
| org.bouncycastle:bcutil-jdk18on | 1.85 | 1.86 |
| org.bouncycastle:bcprov-jdk18on | 1.85 | 1.86 |
| org.bouncycastle:bcutil-jdk18on | 1.85 | 1.86 |

Updates de.fraunhofer.iosb.ilt:FROST-Client-Dynamic from 2.38 to 2.39

Changelog

Sourced from de.fraunhofer.iosb.ilt:FROST-Client-Dynamic's changelog.



Version 2.39


Updates



  • Allowed Sensor.metadata to be any Object.

  • Added STA v1.1 DataArray support.

  • Changed PkValue to be Comparable.


Commits



  • 108e925 Release v2.39


  • 7ac72ea Bump the dependencies group across 1 directory with 10 updates (#237)


  • 8c87cc2 Cleaned up test class & method visibility


  • 6f0d3b8 Allowed Sensor.metadata to be any Object


  • f69dcaa Added STA v1.1 DataArray support


  • fc910eb Changed PkValue to be Comparable


  • f2de9c0 Prepare for next development iteration

  • See full diff in compare view


Updates io.prometheus:prometheus-metrics-bom from 1.8.0 to 1.9.0

Release notes

Sourced from io.prometheus:prometheus-metrics-bom's releases.



v1.9.0



1.9.0 (2026-09-16)


Features



  • support metric name filtering in OpenTelemetry exporter (#2344) (9b0ede8)


Bug Fixes



  • avoid protobuf debug reflection in native images (#2251) (7f899e7)

  • bound HTTPServer request resources (#2333) (33ec556)

  • bound observation buffering during collection (#2336) (43788f5)

  • bound scrape query parameters (#2334) (27e1912)


  • ci: skip benchmark report for skipped runs (#2422) (40eddb0)

  • clarify benchmark regression report verdicts (#2394) (e5fa067)


  • deps: update dependency com.google.guava:guava to v33.7.0-jre (#2387) (bf0db49)


  • deps: update dependency io.dropwizard.metrics:metrics-core to v4.2.40 (#2432) (dd88326)


  • deps: update dependency io.dropwizard.metrics5:metrics-core to v5.0.8 (#2433) (42f3c8a)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.29.0-alpha (#2235) (cf9f702)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.30.0-alpha (#2328) (1ca2716)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.30.0-alpha (#2330) (07623c1)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.31.0-alpha (#2401) (6c26619)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.31.0-alpha (#2402) (ac0d68a)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.31.1-alpha (#2409) (5eea652)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.31.1-alpha (#2410) (0bcef89)


  • deps: update dependency org.apache.tomcat.embed:tomcat-embed-core to v11.0.23 (#2241) (a017f80)


  • deps: update dependency org.apache.tomcat.embed:tomcat-embed-core to v11.0.24 (#2294) (63967bd)


  • deps: update dependency org.apache.tomcat.embed:tomcat-embed-core to v11.0.25 (#2389) (92f8344)


  • deps: update dependency org.apache.tomcat.embed:tomcat-embed-core to v11.0.26 (#2477) (05146c0)


  • deps: update dependency org.springframework.boot:spring-boot-starter-parent to v4.1.1 (#2399) (a0b0880)


  • deps: update jetty monorepo to v12.1.11 (#2279) (4dc54da)


  • deps: update jetty monorepo to v12.1.12 (#2371) (08967e0)


  • deps: update jetty monorepo to v12.1.13 (#2459) (b217f05)


  • deps: update junit-framework monorepo to v6.1.2 (#2300) (5966d1d)


  • deps: update junit-framework monorepo to v6.1.3 (#2374) (d1ade52)


  • deps: update otel.instrumentation.version (#2236) (158230d)


  • deps: update protobuf (#2400) (e2db1ed)


  • deps: update protobuf (#2438) (8ad6fa8)


  • deps: update protobuf to v4.35.1 (#2221) (cf17073)

  • disable micrometer compat build cache (#2457) (6a40eda)

  • drop +Inf bound from OpenTelemetry classic histogram boundaries (#2458) (a3bce9a)


  • exposition: export internal package for OSGi resolution (#2415) (28b503d)


  • httpserver: make scrape error responses secure and configurable (f6d9df5)

  • include counter names in negative value errors (#2315) (ea8f935)

  • include license files in release source jars (#2250) (08cf925), closes #2216

  • keep late observations out of subsequent collection buffers (#2471) (d78b149)

  • keep PR title check required after rebases (#2414) (e3d4c3b)

  • prevent buffer stripe index overflow (#2331) (b6cd000)


<!-- raw HTML omitted -->

... (truncated)

Changelog

Sourced from io.prometheus:prometheus-metrics-bom's changelog.




1.9.0 (2026-09-16)


Features



  • support metric name filtering in OpenTelemetry exporter (#2344) (9b0ede8)


Bug Fixes



  • avoid protobuf debug reflection in native images (#2251) (7f899e7)

  • bound HTTPServer request resources (#2333) (33ec556)

  • bound observation buffering during collection (#2336) (43788f5)

  • bound scrape query parameters (#2334) (27e1912)


  • ci: skip benchmark report for skipped runs (#2422) (40eddb0)

  • clarify benchmark regression report verdicts (#2394) (e5fa067)


  • deps: update dependency com.google.guava:guava to v33.7.0-jre (#2387) (bf0db49)


  • deps: update dependency io.dropwizard.metrics:metrics-core to v4.2.40 (#2432) (dd88326)


  • deps: update dependency io.dropwizard.metrics5:metrics-core to v5.0.8 (#2433) (42f3c8a)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.29.0-alpha (#2235) (cf9f702)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.30.0-alpha (#2328) (1ca2716)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.30.0-alpha (#2330) (07623c1)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.31.0-alpha (#2401) (6c26619)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.31.0-alpha (#2402) (ac0d68a)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.31.1-alpha (#2409) (5eea652)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.31.1-alpha (#2410) (0bcef89)


  • deps: update dependency org.apache.tomcat.embed:tomcat-embed-core to v11.0.23 (#2241) (a017f80)


  • deps: update dependency org.apache.tomcat.embed:tomcat-embed-core to v11.0.24 (#2294) (63967bd)


  • deps: update dependency org.apache.tomcat.embed:tomcat-embed-core to v11.0.25 (#2389) (92f8344)


  • deps: update dependency org.apache.tomcat.embed:tomcat-embed-core to v11.0.26 (#2477) (05146c0)


  • deps: update dependency org.springframework.boot:spring-boot-starter-parent to v4.1.1 (#2399) (a0b0880)


  • deps: update jetty monorepo to v12.1.11 (#2279) (4dc54da)


  • deps: update jetty monorepo to v12.1.12 (#2371) (08967e0)


  • deps: update jetty monorepo to v12.1.13 (#2459) (b217f05)


  • deps: update junit-framework monorepo to v6.1.2 (#2300) (5966d1d)


  • deps: update junit-framework monorepo to v6.1.3 (#2374) (d1ade52)


  • deps: update otel.instrumentation.version (#2236) (158230d)


  • deps: update protobuf (#2400) (e2db1ed)


  • deps: update protobuf (#2438) (8ad6fa8)


  • deps: update protobuf to v4.35.1 (#2221) (cf17073)

  • disable micrometer compat build cache (#2457) (6a40eda)

  • drop +Inf bound from OpenTelemetry classic histogram boundaries (#2458) (a3bce9a)


  • exposition: export internal package for OSGi resolution (#2415) (28b503d)


  • httpserver: make scrape error responses secure and configurable (f6d9df5)

  • include counter names in negative value errors (#2315) (ea8f935)

  • include license files in release source jars (#2250) (08cf925), closes #2216

  • keep late observations out of subsequent collection buffers (#2471) (d78b149)

  • keep PR title check required after rebases (#2414) (e3d4c3b)

  • prevent buffer stripe index overflow (#2331) (b6cd000)

  • redact invalid configuration values (#2335) (7e7e533)


<!-- raw HTML omitted -->

... (truncated)

Commits



  • 71e821c chore(main): release 1.9.0 (#2237)


  • d78b149 fix: keep late observations out of subsequent collection buffers (#2471)


  • 085263b perf: avoid allocating a mapping lambda on every labelValues() call (#2442)


  • 9ec38b7 chore(deps): update otel/opentelemetry-collector-contrib docker tag to v0.161...


  • 05146c0 fix(deps): update dependency org.apache.tomcat.embed:tomcat-embed-core to v11...


  • 59ca1f0 test: focus PR benchmarks on client_java and measure label lookups (#2468)


  • 398d087 fix: show uncertainty in benchmark comparisons (#2476)


  • 8722230 perf: skip snapshot rebuild in mergeDuplicates when names are unique (#2441)


  • ea8f935 fix: include counter names in negative value errors (#2315)


  • fba2007 test: verify buffer recovery after snapshot failures (#2446)

  • Additional commits viewable in compare view


Updates org.eclipse.jetty.ee10:jetty-ee10-servlet from 12.1.12 to 12.1.13

Updates org.jooq:jooq from 3.21.7 to 3.21.8

Updates org.jooq:jooq-codegen from 3.21.7 to 3.21.8

Updates org.jooq:jooq-meta from 3.21.7 to 3.21.8

Updates org.jooq:jooq-codegen from 3.21.7 to 3.21.8

Updates org.jooq:jooq-meta from 3.21.7 to 3.21.8

Updates org.slf4j:jul-to-slf4j from 2.0.18 to 2.0.19

Updates org.slf4j:slf4j-api from 2.0.18 to 2.0.19

Updates org.slf4j:slf4j-api from 2.0.18 to 2.0.19

Updates org.codehaus.mojo:build-helper-maven-plugin from 3.6.1 to 3.6.2

Release notes

Sourced from org.codehaus.mojo:build-helper-maven-plugin's releases.



3.6.2


<!-- raw HTML omitted -->

🐛 Bug Fixes



👻 Maintenance



  • Remove redundant maven-resolver-api dependency and ignore Resolver/SLF4J 2.x in Dependabot (#248) @​slachiewicz


📦 Dependency updates


<!-- raw HTML omitted -->

<!-- raw HTML omitted -->

Commits



  • 813bc7d [maven-release-plugin] prepare release 3.6.2


  • 07d9109 Remove redundant maven-resolver-api and ignore Resolver/SLF4J 2.x in Dependabot


  • 9abd552 Bump org.codehaus.plexus:plexus-utils from 4.0.3 to 4.1.0


  • 3c15526 Bump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml


  • 3b1f104 Bump org.codehaus.mojo:mojo-parent from 96 to 97


  • 1749855 Bump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml


  • 5230041 Bump org.codehaus.plexus:plexus-utils from 4.0.2 to 4.0.3


  • c0e9375 Delete .github/release-drafter.yml


  • 84a839e Bump org.codehaus.mojo:mojo-parent from 95 to 96


  • a85c668 Replace raw NPEx with customized exception message

  • Additional commits viewable in compare view


Updates org.codehaus.mojo:exec-maven-plugin from 3.6.3 to 3.6.4

Release notes

Sourced from org.codehaus.mojo:exec-maven-plugin's releases.



3.6.4


<!-- raw HTML omitted -->

📝 Documentation updates



👻 Maintenance



📦 Dependency updates


<!-- raw HTML omitted -->

<!-- raw HTML omitted -->

Commits



  • 56083f0 [maven-release-plugin] prepare release 3.6.4


  • 57c594b Ignore Maven Resolver >= 2.0 and SLF4J >= 2.0 in Dependabot


  • c2f5d4e Update required module name in jigsaw IT to org.codehaus.plexus.util


  • d227ee6 Bump org.codehaus.plexus:plexus-utils in /src/it/projects/jigsaw


  • 388fd99 Bump org.codehaus.plexus:plexus-utils from 4.0.3 to 4.1.0


  • 30106e8 Stop dependabot from updating test fixtures


  • b6d5eab Bump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml


  • aa98aba Bump org.codehaus.mojo:mojo-parent from 96 to 97


  • 79cfdcd Bump org.apache.maven.plugins:maven-toolchains-plugin


  • 8c58ad6 Fix typo in docs (#531)

  • Additional commits viewable in compare view


Updates org.sonarsource.scanner.maven:sonar-maven-plugin from 5.7.0.6970 to 5.8.0.7211

Release notes

Sourced from org.sonarsource.scanner.maven:sonar-maven-plugin's releases.



5.8.0.7211


Release notes - Sonar Scanner for Maven - 5.8


Maintenance


SCANMAVEN-382 Prepare next development iteration 5.8.0


SCANMAVEN-384 Fix QG broken by the new testing rules


SCANMAVEN-385 Code Quality reorganization from jvm to CI Experience Squad


SCANMAVEN-386 ToggleLockBranch: Add additional-message


SCANMAVEN-387 Code Quality Slack channel reorganization


SCANMAVEN-390 Upgrade orchestrator to version 6.3.0


SCANMAVEN-392 Upgrade jetty test dependencies to version 9.4.58.v20250814


SCANMAVEN-395 Remove scheduled invocation of sonar:sonar shorthand test


SCANMAVEN-397 Replace Maven 4.0.0-rc-5 in ITs with Maven 4.0.0-rc-6


SCANMAVEN-398 Upgrade orchestrator to version 6.4.0


SCANMAVEN-399 Update sonar-scanner-java-library to 4.1.2.1663


SCANMAVEN-401 Upgrade Jetty used by e2e tests


SCANMAVEN-402 Upgrade orchestrator to version 6.4.3.4676


Feature


SCANMAVEN-403 Releasability status fails on property-dump-plugin version


Commits



  • 7347a92 SCANMAVEN-403 Releasability status fails on property-dump-plugin version (#426)


  • 002f55c SCANMAVEN-402 Upgrade orchestrator to version 6.4.3.4676 (#425)


  • fc7515f SCANMAVEN-401 Upgrade Jetty used by e2e tests (#424)


  • 16dedb3 SCANMAVEN-399 Update sonar-scanner-java-library to 4.1.2.1663 (#421)


  • ad81956 SCANMAVEN-397 Upgrade Maven 4 to 4.0.0-rc-6 in tests (#420)


  • 86e9516 SCANMAVEN-398 Upgrade orchestrator to version 6.4.0 (#419)


  • c26335c SCANMAVEN-395 Remove scheduled invocation of sonar:sonar shorthand test (#417)


  • 6a79ca6 SCANMAVEN-392 Upgrade jetty test dependencies to version 9.4.58.v20250814 (#416)


  • 57bb131 SCANMAVEN-390 Upgrade orchestrator to version 6.3.0 (#414)


  • 9d50b6d GHA-355 Add statuses: write permission for release-lock feature (#412)

  • Additional commits viewable in compare view


Updates com.diffplug.spotless:spotless-maven-plugin from 3.10.1 to 3.10.2

Release notes

Sourced from com.diffplug.spotless:spotless-maven-plugin's releases.



Maven Plugin v3.10.2


Fixed




  • <shortenFullyQualifiedTypes> now shortens fully-qualified types used in expression contexts (such as static method calls, static fields, and enum constants) while avoiding imports that would change how existing unqualified type references resolve. (#3039)

  • Eclipse JDT formatter step no longer fails with NoClassDefFoundError when lombok is active as a JVM agent (e.g. -javaagent:lombok.jar in Eclipse/VS Code/Cursor). (#2795)


Commits



  • dc2a4cb Published maven/3.10.2


  • 876c8c4 Published gradle/8.10.2


  • ff28375 Published lib/4.10.2


  • e260aa7 shortenFullyQualifiedTypes: preserve unqualified type resolution (#3037)


  • 5a2cdca Update changelogs.


  • 98ca50e Merge remote-tracking branch 'origin/main' into 3033-unqualified-type-collision


  • 9591d7e Resolve interopability with spotless, lombok and VSCode (#3038)


  • 5842e1b shortenFullyQualifiedTypes: shorten FQTs in expression context (#3039)


  • e7f5b60 Add changelog entries


  • 79ff6c7 Resolve interopability with spotless, lombok and VSCode

  • Additional commits viewable in compare view


Updates org.bouncycastle:bcpkix-jdk18on from 1.85 to 1.86

Changelog

Sourced from org.bouncycastle:bcpkix-jdk18on's changelog.



Bouncy Castle Crypto Package - Release Notes


1.0 Introduction


The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. The package is organised so that it contains a light-weight API suitable for use in any environment (including the J2ME) with the additional infrastructure to conform the algorithms to the JCE framework.


2.0 Release History


<!-- raw HTML omitted --><!-- raw HTML omitted -->


2.1.1 Version


Release: 1.87

Date: 2026, TBD


2.1.2 Defects Fixed




  • A KeyAgreement asked for its shared secret before doPhase returned data rather than refusing. javax.crypto.KeyAgreement specifies IllegalStateException for that state, but nothing in the provider tracked it, so each SPI handed back whatever its result field held: for Diffie-Hellman that was the private value itself - engineInit seeded result with x, so generateSecret() returned the private exponent padded to the prime's length and generateSecret("AES") an all-zero key taken from that padding - while ECDH returned null and its named-algorithm overload raised NullPointerException. BaseAgreementSpi now records whether a doPhase has completed the agreement since the last init and refuses the request with an IllegalStateException naming the algorithm, so every family in the provider - DH, ECDH and ECMQV, the SM2 exchange, both ECGOST families, XDH, SM9 and NewHope - answers the same way, and the DH SPI no longer holds the private value in that field at all.




  • Mac.getInstance and KeyGenerator.getInstance by the HMAC SHA-512/224 and SHA-512/256 object identifiers (1.2.840.113549.2.12 and .13) failed, although the same algorithms resolved by name and the matching SecretKeyFactory aliases were registered: the SHA512 mappings called addHMACAlgorithm for the two truncated variants without the addHMACAlias that registers their OIDs against Mac and KeyGenerator. Both are now aliased, as every other HMAC in that class already was.




  • A KTSParameterSpec naming an HKDF key-derivation function with a parameters field - a form the provider does not service - was accepted at Cipher init and then failed out of wrap or unwrap with an unchecked IllegalStateException neither method declares. The KTS key-wrapping Ciphers (ML-KEM, Classic McEliece, FrodoKEM, the composite KEM and RSA-KEM) now validate the spec's KDF when they take it, reporting an unserviceable one as the InvalidAlgorithmParameterException engineInit declares, which is what the javax.crypto.KEM services already did through KdfUtil.resolveKemSpec.




  • A DTLS handshake deadlocked when a handshake message ahead of the peer's ChangeCipherSpec (a client's CertificateVerify, say) was lost while the ChangeCipherSpec and Finished behind it arrived: the record layer moved its read epoch on at the ChangeCipherSpec and then discarded every retransmission of the lost message as belonging to the old epoch, whose records are only accepted once the handshake has completed. Each side then waited on the other until a handshake timeout, if one was configured, ended it. Every client-authenticated handshake, and every handshake in which the server issues a NewSessionTicket, was exposed. Until the handshake completes, handshake records from the current epoch are now still accepted after the read epoch has moved on, and each message is checked against the epoch of the record that carried it. The DTLS loopback tests now run their handshakes at 10% datagram loss in each direction, with a client-authenticated handshake at 25%.




  • The lightweight SubjectPublicKeyInfoFactory and PrivateKeyInfoFactory encoded a GOST R 34.10-2012 key on one of the legacy CryptoPro curves under id-GostR3410-2001, although RFC 9215 sec. 4.2 permits those curves for 2012 keys. The digestParamSet now decides: a GOST R 34.11-94 parameter set means 2001 (RFC 4491 sec. 2.3.2), a GOST R 34.11-2012 digest or none means 2012 with 256/512 taken from the curve field size, and any other value is rejected. GOST3410PublicKeyAlgParameters treats digestParamSet as OPTIONAL on both read and write per RFC 9215, and PrivateKeyInfoFactory now passes attributes through for ECGOST3410 keys (bc-csharp github #707).




  • The name-constraint host canonicalisation removed a single RFC 1034 root-label dot, the only empty label a name may legally carry, but nothing refused the ones that are not legal: a dNSName, rfc822Name host or uniformResourceIdentifier host such as "example.com.." kept a phantom empty label after the strip and so matched no constraint at all, escaping an excluded subtree naming the host it appears to carry. A tested name whose host carries an empty label - a second trailing dot, a doubled dot or a leading dot - is now refused outright wherever a constraint of that type is in force, rather than canonicalised into a name it is not: removing the extra dots would decide on the caller's behalf that "example.com.." names example.com, which is not how a consumer resolving or comparing the name reads it, and refusing fails closed in both directions where canonicalising would newly admit such a name under a permitted subtree. The single trailing dot is canonicalised as before, a bare "." remains the root label rather than an empty one, and the guard is scoped to the host, so the doubled dot a quoted local part may legally carry is unaffected. Constraints are untouched - one may still begin with a dot, which is how this implementation spells "subdomains only" (github PR #2436).




2.1.3 Additional Features and Functionality


2.1.4 Additional Notes



  • The sources and javadoc jars of the Ant-built distributions (jdk14, jdk15to18 and jdk13) no longer carry test material. Each module's javadoc target copies the package documentation it needs - org/bouncycastle/<!-- raw HTML omitted -->//.html - back into the module source directory that has already been compiled from, and zip-src zips that directory afterwards, so every test package's package.html arrived in the sources jar by that route; javadoc-util additionally copied org/bouncycastle/asn1/isismtt//.java, which put test classes into the bcutil javadoc as generated pages, and javadoc-pg deliberately copied the gpg and bcpg test sources in order to document them. Separately the source copies excluded test material only one directory deep and only for .java, because Ant reads * as an any-depth wildcard just where it is a whole path segment, so anything nested further or with another extension - the PEM certificate fixtures under org/bouncycastle/est/test/san corrected in 1.86, and an ICAO master list under org/bouncycastle/asn1/icao/test - went through. The source and javadoc copies of every module now exclude test directories at any depth, and javadoc-pg no longer documents the test packages. org.bouncycastle.util.test is unaffected and still ships in the bcprov binary, sources and javadoc jars, as it does from the Gradle build: it is the SimpleTest framework the light-weight API's own test classes are written against, not test material of the distribution. No binary changes - the classes and resources of every Ant-built jar are identical to those of the 1.86 release - and the Gradle-built jdk18on artifacts never carried any of this.


<!-- raw HTML omitted --><!-- raw HTML omitted -->


2.2.1 Version


Release: 1.86

Date: 2026, 11th September.


2.2.2 Defects Fixed



  • The high-level OpenPGP API let a subkey inherit the primary key's Key Flags when its own Subkey Binding signature carried none, so a subkey bound with no flags counted as signing-capable for one check while the cross-certification check RFC 9580 sec. 5.2.1.8 requires of a signing subkey saw none and was skipped - letting a third party's public signing subkey be bound to an attacker's primary key and that party's genuine signatures verify under the attacker's identity. Flags are no longer inherited (CVE-2026-71887).

  • The high-level OpenPGP API used a version 6 key carrying no valid Direct Key signature, falling back to the primary user ID binding as it correctly does for version 4. RFC 9580 sec. 5.2.3.10 requires the opposite, and since a v6 certificate carries its expiration and preferences there, stripping that one packet silently dropped them - the certificate went on offering subkeys of a key set to expire. isBoundBy now requires a valid Direct Key self-signature before any v6 component is treated as bound; version 4 is unaffected.

  • The high-level OpenPGP API ignored the OpenPGPPolicy a caller had configured when verifying signatures on an inline message: OpenPGPMessageInputStream took the policy from the implementation's own default rather than from the processor doing the verification, so a hardened policy had no bearing on acceptance and getSignatures() reported isTestedCorrect() true for a signature that policy rejects. Both the one-pass and prefixed-signature paths now read the configured policy.

  • The high-level OpenPGP API went on offering the subkeys of a certificate whose primary key had expired, the binding check evaluating only a subkey's own Subkey Binding signature - so the certificate contradicted itself, reporting the primary unbound while still handing out its subkeys. The primary key's expiration now applies to the whole certificate, as GnuPG and Sequoia treat it, and a subkey no longer inherits the primary's validity period, which RFC 9580 sec. 5.2.3.13 counts from the creation time of the key the carrying signature is made on.

  • OpenPGPDocumentSignature.isValidAt(Date) reported a data signature as valid past the signature's own Signature Expiration Time (RFC 9580 sec. 5.2.3.18): it checked that the signature was correct and the issuing key bound and signing-capable at that date, but never the signature's own expiration, so it disagreed with isEffectiveAt() on the same object and with its own javadoc. isValid() and isValid(policy), which evaluate at creation time, are unchanged.

  • The lightweight LMSSigner and HSSSigner refused a key wrapped in ParametersWithRandom, which is how BcContentSignerBuilder passes one once setSecureRandom() has been called, so BcHssLmsContentSignerBuilder failed with "Incorrect Key Parameters" and the two signers raised ClassCastException. All three now unwrap it, as the ML-DSA and SLH-DSA signers already did; the random is accepted and ignored, LMS deriving its message randomiser deterministically from the seed and one-time index.

  • LMS signature verification did not apply two checks RFC 8554 sec. 5.4.2 requires before a signature is processed: step 2g, refusing a signature whose LMS typecode is not the public key's - without it a signature claiming a height-25 parameter set drove a 25-level computation against a height-5 key - and step 2i, refusing a leaf number outside the tree. Neither was a forgery, but both are attacker-chosen work the specification says to refuse up front. Both are now checked.

  • The LMS and HSS key parameter classes now apply at construction the checks their decoders apply, so a key built directly cannot be one the decoder would refuse: LMSPrivateKeyParameters accepted an identifier of any length where the decoder reads exactly 16 bytes, and left q, maxQ and the seed length unchecked, while HSSPrivateKeyParameters checked neither its level count nor that it had a component key and chaining signature per level. The decoders now report a bad version or seed length as IOException rather than IllegalStateException.

  • In the LMS JCE layer, LMSKeyGenParameterSpec.fromNames knew all twenty LMS parameter-set names but only four of the sixteen LM-OTS ones, so none of the SP 800-208 n24 or SHAKE sets could be named; all sixteen are now present. initialize(int, SecureRandom) now reports InvalidParameterException as the JCA specifies, and BCLMSPrivateKey.getIndex takes the exhaustion check and the index read under one monitor.

  • KeyPairGenerator.initialize(int, SecureRandom) is documented to raise InvalidParameterException when the key size is not one the generator supports, and thirty of them raised a bare IllegalArgumentException instead. Every generator in BCPQC, and the ML-DSA, ML-KEM, SLH-DSA, Classic McEliece, FrodoKEM, NTRU and composite ones in the BC provider, now raise the documented type - which extends IllegalArgumentException, so existing catches still match. The two RSA generators translate the lightweight refusal through a new SecurityExceptions.invalidParameterException factory.


<!-- raw HTML omitted -->

... (truncated)

Commits


Updates ...

Description has been truncated

0 total changed files
You've made it to the end of the scroll.
Like the credits, but with fewer stunts.