Skip to content

feature/INT-1723 - Bouncy Castle dependabot alert fix - #682

Merged
david-ruiz-cko merged 1 commit into
masterfrom
feature/INT-1723
Oct 2, 2026
Merged

david-ruiz-cko merged 1 commit into
masterfrom
feature/INT-1723

Conversation

@david-ruiz-cko

@david-ruiz-cko david-ruiz-cko commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

SonarCube version bump

SonarCube version bump to solve bouncy castle dependabot alerts.

What the alerts were

Both are for org.bouncycastle:bcprov-jdk18on < 1.85, with the patch in 1.85. Dependabot points to settings.gradle, so it's a build plugin dependency, not one the SDK itself uses. Tracing the build's plugin dependencies showed the only source was the SonarQube plugin: org.sonarqube 7.3.1 → sonar-scanner-java-library:4.1.1 → bcprov-jdk18on:1.84.

Why the bump fixes them

Plugin 7.5.0 now uses a different scanner library (sonar-scanner-java-library-shaded:4.2.1.1698). That library bundles Bouncy Castle 1.85.2, renamed into its own internal package, instead of pulling in bcprov 1.84.

@david-ruiz-cko
david-ruiz-cko requested a review from a team October 2, 2026 10:44
@agent-wall-e

agent-wall-e Bot commented Oct 2, 2026

Copy link
Copy Markdown

🟡 Risk Classification: MINOR

Approval route: AI Review + Human Approval
Rollback controls: Staged rollout + rollback

Classification reasons

  • no_low_class_matched
  • prod_source_modified

Operational gates

  • ✅ jira_ticket (INT-1723)
  • ✅ independent_review

Files analysed: 1


wall-e 2026.06.19-02 · policy 6b4ce2b3b45a…

@agent-wall-e

agent-wall-e Bot commented Oct 2, 2026

Copy link
Copy Markdown
🔬 Debug — why this classification?

Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.

Reason code Kind Clause Meaning
no_low_class_matched informational §2.2 (fall-through) None of the deterministic Low classes (§2.2.3, §2.2.4, §2.2.7, docs-only) applied; classifier fell through to LLM evaluation.
prod_source_modified informational §2.1 M7 (informational) At least one file is non-doc, non-test, non-IaC — i.e. application source code was modified.

Kinds:

  • classifying — this rule contributed to the chosen tier.
  • informational — context only; did not by itself decide the tier.

See issue #3 for the proposal to formalise this map as Appendix A of the standards doc.

wall-e 2026.06.19-02 · debug

@agent-wall-e

agent-wall-e Bot commented Oct 2, 2026

Copy link
Copy Markdown

🟢 Advisory review: Looks good to me

This PR still needs a human approval — wall-e cannot auto-approve it. For what it's worth, I read the diff and found nothing I'd block on.

Updates the SonarQube Gradle plugin from 7.3.1.8318 to 7.5.0.8588, likely to pick up a transitive Bouncy Castle dependency upgrade that addresses the security alert.

What I checked

  • The single-line change is a version bump of the org.sonarqube plugin from 7.3.1.8318 to 7.5.0.8588, which is consistent with the stated intent of resolving a Bouncy Castle dependabot alert via a transitive dependency upgrade in the SonarQube plugin.
  • The diff does not show a dependency lock file or version catalog update alongside this change; if the project uses dependency locking, that artifact would need to be regenerated for the fix to take effect.
  • No tests, logic, or runtime behaviour are touched by this change.

This is not an approval. wall-e cannot auto-approve this PR — it is an opinion to help whoever does. Advisory review · us.anthropic.claude-sonnet-4-6 · wall-e 2026.06.19-02

@sonarqubecloud

sonarqubecloud Bot commented Oct 2, 2026

Copy link
Copy Markdown

@david-ruiz-cko
david-ruiz-cko merged commit 7335acf into master Oct 2, 2026
6 checks passed
@david-ruiz-cko
david-ruiz-cko deleted the feature/INT-1723 branch October 2, 2026 13:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants