[OpenNMS/opennms] b1a5c9: NMS-20092: Remove EOL BouncyCastle jdk15on and SAM...

Marshall Massengill via opennms-cvs <[email protected]> Fri, 31 Jul 2026 16:31:36 -0700
Newsgroups gmane.network.opennms.cvs
Message-ID <OpenNMS/opennms/push/refs/heads/release-36.x/[email protected]>
  Branch: refs/heads/release-36.x
  Home:   https://github.com/OpenNMS/opennms
  Commit: b1a5c92b9f1251db30f6f8e438684fb5b8624ed0
      https://github.com/OpenNMS/opennms/commit/b1a5c92b9f1251db30f6f8e438684fb5b8624ed0
  Author: Marshall Massengill <[email protected]>
  Date:   2026-07-31 (Fri, 31 Jul 2026)

  Changed paths:
    M dependencies/spring-security/pom.xml
    M pom.xml

  Log Message:
  -----------
  NMS-20092: Remove EOL BouncyCastle jdk15on and SAML-era deps from spring-security (#8683)

bcprov-ext/bcprov/bcpkix-jdk15on 1.70 shipped a second, EOL crypto
provider alongside the jdk18on 1.84 the rest of the build uses. esapi
and xmlsec lost their last consumer when spring-security-saml2-core
was dropped; their orphaned root-pom property/dependencyManagement
entries go too. Removing esapi also drops its transitive baggage
(antisamy, bcutil-jdk15on, neko-htmlunit, xom, httpclient5/httpcore5)
- 12 jars out of lib/ total, verified by diffing the assembled lib/
against a pre-change baseline. Login + authenticated REST verified on
a local build. LDAP/Kerberos spring-security artifacts untouched.



To unsubscribe from these emails, change your notification settings at https://github.com/OpenNMS/opennms/settings/notifications


_______________________________________________
Please read the OpenNMS Mailing List FAQ:
http://www.opennms.org/wiki/index.php?page=MailingListFaq
opennms-cvs mailing list

To *unsubscribe* or change your subscription options, see the bottom of this page:
https://lists.sourceforge.net/lists/listinfo/opennms-cvs