Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Third-party Dependency Upgrades for APIM 4.4.0 #3105

Open
YasasRangika opened this issue Sep 10, 2024 · 5 comments
Open

Third-party Dependency Upgrades for APIM 4.4.0 #3105

YasasRangika opened this issue Sep 10, 2024 · 5 comments

Comments

@YasasRangika
Copy link

Description

This issue is created to track the third-party dependency upgrades for the APIM 4.4.0 release. Each upgraded dependency will be mentioned in the comments.

Affected Component

APIM

Version

4.4.0

Related Issues

No response

Suggested Labels

No response

@YasasRangika
Copy link
Author

YasasRangika commented Sep 10, 2024

[STATUS UPDATE]

Provided a docker image of the APIM-4.4.0-m2 pack to the security team for the JFrog Analysis report.

@npamudika
Copy link

Refer #3014

@YasasRangika
Copy link
Author

[STATUS UPDATE]

Upgrade CXF version from 3.6.3 to 3.6.4:

wso2/carbon-apimgt#12556
wso2/product-apim#13530
wso2/carbon-deployment#401

@YasasRangika
Copy link
Author

[STATUS UPDATE]

Upgrade bcprov-jdk18on and bcpkix-jdk18on Bouncy Castle dependencies from 1.77.0.wso2v1 to 1.78.1.wso2v1. Also, upgrade the bc-fips version from 1.0.2.4 to 1.0.2.5.

carbon-multitenancy PR: wso2/carbon-multitenancy#270
wso2-synapse PR: wso2/wso2-synapse#2217
carbon-apimgt PR: wso2/carbon-apimgt#12567
carbon-kernel PR: wso2/carbon-kernel#4074
product-apim PR: wso2/product-apim#13532

@YasasRangika
Copy link
Author

[STATUS UPDATE]

Upgraded the Tomcat versions from 9.0.85.wso2v1 to 9.0.94.wso2v1 and tested the portals with the major REST APIs.

Orbit PR: wso2/orbit#1132
carbon-kernel PR: wso2/carbon-kernel#4075

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants