feature/INT-1723 - Bouncy Castle dependabot alert fix - #682
Conversation
🟡 Risk Classification: MINORApproval route: AI Review + Human Approval Classification reasons
Operational gates
Files analysed: 1 wall-e 2026.06.19-02 · policy |
🔬 Debug — why this classification?Each reason code emitted by the classifier, its source clause in the AI in SDLC Control Framework, and what it means.
Kinds:
See issue #3 for the proposal to formalise this map as Appendix A of the standards doc. wall-e 2026.06.19-02 · debug |
🟢 Advisory review: Looks good to meThis PR still needs a human approval — wall-e cannot auto-approve it. For what it's worth, I read the diff and found nothing I'd block on. Updates the SonarQube Gradle plugin from 7.3.1.8318 to 7.5.0.8588, likely to pick up a transitive Bouncy Castle dependency upgrade that addresses the security alert. What I checked
This is not an approval. wall-e cannot auto-approve this PR — it is an opinion to help whoever does. Advisory review · us.anthropic.claude-sonnet-4-6 · wall-e 2026.06.19-02 |
|



SonarCube version bump
SonarCube version bump to solve bouncy castle dependabot alerts.
What the alerts were
Both are for org.bouncycastle:bcprov-jdk18on < 1.85, with the patch in 1.85. Dependabot points to settings.gradle, so it's a build plugin dependency, not one the SDK itself uses. Tracing the build's plugin dependencies showed the only source was the SonarQube plugin: org.sonarqube 7.3.1 → sonar-scanner-java-library:4.1.1 → bcprov-jdk18on:1.84.
Why the bump fixes them
Plugin 7.5.0 now uses a different scanner library (sonar-scanner-java-library-shaded:4.2.1.1698). That library bundles Bouncy Castle 1.85.2, renamed into its own internal package, instead of pulling in bcprov 1.84.