[deps] update jruby-openssl to 0.14.2#7867
Conversation
|
There seem to be a few flakes here, but imagine they might be OK after a rerun? |
|
@chadlwilson only one failure seems valid. I am guessing newer openssl is larger than before so we exceed some size check. This is not a real problem though unless we changed packaging of that gem and it has extra crud in it. @kares is this something we should update yet? |
|
@enebo Hmm, that seems odd. I'd actually expect it should reduce jar size by about 3 MB as they removed a whole lot of stuff from Bouncy Castle in this release which was quite a big component within jruby-complete etc if I recall correctly. Might require some digging to see why this is. |
|
OK, so the increase does seem to be expected. While BouncyCastle This is mainly due to addition of a lot of post quantum crypto support, even though some algorithms have been removed in https://rubygems.org/gems/jruby-openssl/versions/0.14.1-java 8.58 MB bcprov-jdk18on raw jar sizes So while unfortunate, the size increase is expected 😬 |
Signed-off-by: Chad Wilson <chadw@thoughtworks.com>
|
@chadlwilson Thanks for doing that sleuthing. Now we will just see what @kares has to say. |
kares
left a comment
There was a problem hiding this comment.
Thanks for taking care of this Chad, I do recall you mentioned code being removed from BC.
But indeed as I updated BC in JOSSL noticed a size increase, did not investigate why.
I do assume it's legit - seems the bcprov jar had more than 2MB increase since 1.71.
Signed-off-by: Chad Wilson <chadw@thoughtworks.com>
|
for the record, also merged the changes for next 9.3: #7877 |
See https://github.com/jruby/jruby-openssl/releases/tag/v0.14.2
Not sure from @kares if this is "ready", but there is some CVE noise (that doesn't affect JRuby) mentioned at jruby/jruby-openssl#278 within the bundled bouncy castle version which would be nice to get rid of on the next JRuby
9.4.xrelease.