Patch release-plugin crypto and utility dependencies - #187
Merged
Merged
Conversation
This was referenced Sep 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The resolved GPG/Central plugin closures contained advisory matches in Bouncy Castle 1.81 and Plexus Utils 3.5.1/3.6.0. Align the three BC modules at 1.86 and both Plexus uses at compatible 3.6.2, confined to release plugin dependencies.
Validation on implementation commit
d110c3594e3c78e46d2b652adadb356df64bf2cb:0cb11a6a3bf2c842793c135df62fb9e9eaf2fd64found no actionable issues, independently checking the signed bundles, reproducibility hashes and dependency closure. All 28 checks also passed on that final evidence-only head before merge.The checked-in batch 04 validation record contains the full coordinate list and payload/bundle hashes. This does not certify unrelated build dependencies or live Central transport. #111 retains namespace access and a validated-then-dropped staging rehearsal.
Follow-up to #95/#103 and batch 04 in #169.