From c44c82719312315b88e0772b3bbd6b9ca92b6524 Mon Sep 17 00:00:00 2001 From: pandeymangg Date: Wed, 30 Sep 2026 15:40:18 +0530 Subject: [PATCH] fix(security): floor Bouncy Castle, freemarker and commons-lang3 in the build toolchain Clears Dependabot alerts #52-#55. All four are build tooling only; none reaches the published AAR. - bcprov 1.84: Kotlin 2.4's kotlinBouncyCastleConfiguration, an :android configuration the securityFloors map did not cover. - freemarker 2.3.32: Dokka 2.2.0's generator runtime. - commons-lang3 3.16.0: brought onto AGP's plugin classpath by the commons-compress 1.27.1 floor. --- android/build.gradle.kts | 9 +++++++-- build.gradle.kts | 3 +++ gradle/libs.versions.toml | 13 +++++++++---- 3 files changed, 19 insertions(+), 6 deletions(-) diff --git a/android/build.gradle.kts b/android/build.gradle.kts index 3dc1629..3f6a805 100644 --- a/android/build.gradle.kts +++ b/android/build.gradle.kts @@ -36,8 +36,9 @@ jacoco { // Raise known-vulnerable transitive dependencies of the build toolchain to patched // versions. None of these is a dependency of the SDK itself - they are pulled in by the -// Android Gradle Plugin's Unified Test Platform (netty, protobuf) and by Dokka's engine -// (jackson, jsoup), so the published AAR and its POM are unaffected. +// Android Gradle Plugin's Unified Test Platform (netty, protobuf), by Dokka's engine +// (jackson, jsoup, freemarker) and by the Kotlin plugin's signing helpers (Bouncy Castle), +// so the published AAR and its POM are unaffected. // // These are floors, not overrides: `useVersion` on its own would also drag a *newer* // version back down, so anything at or above the floor is left alone and only older @@ -54,6 +55,10 @@ run { "com.fasterxml.jackson.dataformat" to libs.versions.jackson.get(), "com.fasterxml.jackson.module" to libs.versions.jackson.get(), "org.jsoup" to libs.versions.jsoup.get(), + "org.freemarker" to libs.versions.freemarker.get(), + // Kotlin 2.4's `kotlinBouncyCastleConfiguration` backs its PGP key and signing check + // tasks. This build never runs them, but the dependency graph still resolves it. + "org.bouncycastle" to libs.versions.bouncycastle.get(), ) fun isBelowFloor(current: String?, floor: String): Boolean { diff --git a/build.gradle.kts b/build.gradle.kts index df1330b..d4a2609 100644 --- a/build.gradle.kts +++ b/build.gradle.kts @@ -20,6 +20,9 @@ buildscript { add("classpath", "org.bitbucket.b_c:jose4j:${libs.versions.jose4j.get()}") add("classpath", "org.jdom:jdom2:${libs.versions.jdom2.get()}") add("classpath", "org.apache.commons:commons-compress:${libs.versions.commonsCompress.get()}") + // Not from AGP directly: commons-compress 1.26+ depends on it, so the floor above + // brings it onto this classpath. + add("classpath", "org.apache.commons:commons-lang3:${libs.versions.commonsLang3.get()}") } } } diff --git a/gradle/libs.versions.toml b/gradle/libs.versions.toml index 42a420a..c822f77 100644 --- a/gradle/libs.versions.toml +++ b/gradle/libs.versions.toml @@ -33,14 +33,17 @@ dokka = "2.2.0" # resolved independently: # # - build.gradle.kts (root buildscript) - AGP's own plugin classpath. gRPC/Netty, Bouncy -# Castle, commons-compress, jose4j and JDOM live here. This is the classpath Dependabot -# reports against, attributed to settings.gradle.kts. +# Castle, commons-compress (and its commons-lang3), jose4j and JDOM live here. # - android/build.gradle.kts (resolutionStrategy) - the :android project's configurations, -# including AGP's Unified Test Platform, plus Dokka's engine (jackson, jsoup). +# including AGP's Unified Test Platform, Dokka's engine (jackson, jsoup, freemarker) and +# the Kotlin plugin's signing helpers (Bouncy Castle again). +# +# Dependabot reports both, attributing every alert to settings.gradle.kts - check which +# classpath a version is on before adding a floor. # # Dependabot does not track these: its Gradle parser only reaches [versions] through a # `version.ref` in [libraries]/[plugins], and nothing references them. Re-check them by -# hand when `agp` or `dokka` is upgraded - because they are floors, one at or below what the +# hand when `agp`, `kotlin` or `dokka` is upgraded - because they are floors, one at or below what the # tool already ships is a no-op, so a stale entry is inert rather than harmful. netty = "4.1.138.Final" protobuf = "3.25.9" @@ -50,6 +53,8 @@ bouncycastle = "1.85" jose4j = "0.9.6" jdom2 = "2.0.6.1" commonsCompress = "1.27.1" +commonsLang3 = "3.21.0" +freemarker = "2.3.35" [libraries] androidx-core-ktx = { group = "androidx.core", name = "core-ktx", version.ref = "coreKtx" }