Skip to content

AP-25728: Bump com.box:box-java-sdk component to 4.16.4#31

Open
3nol wants to merge 2 commits intomasterfrom
bug/AP-25728-update-com-box-box-java-sdk
Open

AP-25728: Bump com.box:box-java-sdk component to 4.16.4#31
3nol wants to merge 2 commits intomasterfrom
bug/AP-25728-update-com-box-box-java-sdk

Conversation

@3nol
Copy link
Contributor

@3nol 3nol commented Mar 5, 2026

AP-25728 (Update com.box:box-java-sdk to 4.11.1)

@3nol 3nol requested a review from a team as a code owner March 5, 2026 10:23
@3nol 3nol requested review from Copilot and knime-ghub-bot and removed request for a team and Copilot March 5, 2026 10:23
@3nol 3nol force-pushed the bug/AP-25728-update-com-box-box-java-sdk branch from 04a33b9 to 5de57c6 Compare March 6, 2026 10:38
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR bumps the com.box:box-java-sdk dependency from 4.10.0 to 4.11.1 and replaces the transitive jose4j 0.9.4 dependency with a directly specified 0.9.6 version to address known CVEs (AP-25728).

Changes:

  • Updated box-java-sdk from 4.10.0 to 4.11.1 in the Maven POM, and excluded its transitive jose4j dependency to replace it with a CVE-patched version (0.9.6).
  • Updated all Eclipse/OSGi configuration files (.classpath, MANIFEST.MF, build.properties) and license CSV to reflect the new library versions consistently.
  • Fixed indentation (spaces → tabs) in the copy-src-jars execution block of the POM.

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated no comments.

Show a summary per file
File Description
org.knime.ext.box.filehandling/libs/fetch_jars/pom.xml Bumped box-java-sdk to 4.11.1, excluded transitive jose4j, added jose4j 0.9.6 directly, fixed indentation
org.knime.ext.box.filehandling/libraries_license/licenses.csv Updated library versions in license tracking file
org.knime.ext.box.filehandling/build.properties Updated jar filenames to new versions
org.knime.ext.box.filehandling/META-INF/MANIFEST.MF Updated Bundle-ClassPath jar references to new versions
org.knime.ext.box.filehandling/.classpath Updated classpath entries to new jar and source jar versions

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

You can also share your feedback on Copilot code review. Take the survey.

@3nol 3nol force-pushed the bug/AP-25728-update-com-box-box-java-sdk branch from 5de57c6 to 6df4057 Compare March 6, 2026 13:20
@3nol 3nol changed the title AP-25728: Bump com.box:box-java-sdk component to 4.11.1 AP-25728: Bump com.box:box-java-sdk component to 4.16.4 Mar 6, 2026
@3nol 3nol force-pushed the bug/AP-25728-update-com-box-box-java-sdk branch from 6df4057 to 7f0a472 Compare March 15, 2026 22:05
3nol added 2 commits March 20, 2026 15:37
* Use "org.bouncycastle.[bcpkix|bcprov|bcutil]" from our target platform.

AP-25728 (Update com.box:box-java-sdk to 4.11.1)
@3nol 3nol force-pushed the bug/AP-25728-update-com-box-box-java-sdk branch from 7f0a472 to 41a3a46 Compare March 20, 2026 14:37
@sonarqubecloud
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants