Skip to content

Conversation

dependabot[bot]
Copy link

@dependabot dependabot bot commented on behalf of github Jul 31, 2025

Bumps software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk from 1.0.0-SNAPSHOT to 1.5.0.

Release notes

Sourced from software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk's releases.

Fix CA override functions

Fix the issue where "overrideDefaultTrustStore" functions did not actually override the system trust store on Linux and Apple platforms.

Add Greengrass APIs for resource management

No release notes provided.

Reconnect Timeout

  • Support configurable reconnect timeout

keepAliveMs -> keepAliveSecs

  • Deprecated withKeepAliveMs, also fixed the bug in it
  • Introduce withKeepAliveSecs

Greengrass IPC client update

  • New APIs added to the Greengrass IPC client (#163)

Windows SNI fix on root CA override

  • On Windows, perform SNI/server cert chain check even if the the root CA has been overridden

Improved proxy suport

  • Direct mqtt connections may now go through an http proxy.
  • Bugfixes from CRT version update:
    • Fix tls context initialization errors due to pem-sanitization bug
    • Fix ECS credentials provider

Http and Windows fixes

Updating aws-crt-java to pick up the following changes:

  • BUGFIX: More validation of HTTP/1.1 messages.
  • BUGFIX: High resolution clock fix on Windows.
  • BUGFIX: Non-ascii file open fix on Windows.
  • BUGFIX: Support non-desktop Windows.
  • BUGFIX: Fixing sending of S3 abort-multipart-upload message

Aws-lc and mqtt race condition fixes

  • Transition from openssl to aws-lc as the native crypto implementation on linux
  • Fixed a significant number of race conditions in the mqtt implementation

Updated Greengrass IPC client

  • Updated Greengrass IPC client (#149)

TLS alert fix for device advisor

  • Pull in s2n shutdown fix via crt; add resource waits on samples
  • Add long operation timeout to support tls shutdown delay for device advisor

Protocol Operation Timeout Added

  • withProtocolOperationTimeoutMs method added to AwsIotMqttConnectionBuilder, which will control timeout value for requests that response is required on healthy connection. If a response is not received within this interval, the request made by the connection will fail. Applied to publish (QoS>0) and unsubscribe

EventStreamRPC connect ack bug fix

  • Fixes connect ack bug released recently in EventStream RPC

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk](https://github.com/awslabs/aws-iot-device-sdk-java-v2) from 1.0.0-SNAPSHOT to 1.5.0.
- [Release notes](https://github.com/awslabs/aws-iot-device-sdk-java-v2/releases)
- [Commits](https://github.com/awslabs/aws-iot-device-sdk-java-v2/commits/v1.5.0)

---
updated-dependencies:
- dependency-name: software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk
  dependency-version: 1.5.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jul 31, 2025
@jpeaks-eroad
Copy link

Logo
Checkmarx One – Scan Summary & Details940f7487-9304-4711-93ae-693cb3839771

New Issues (6)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
HIGH CVE-2025-52999 Maven-com.fasterxml.jackson.core:jackson-core-2.12.0
detailsRecommended version: 2.15.0
Description: The jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions pr...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: OoMUT%2FtKUorOHhy%2BuFqfpvUx2zDL%2FxihnFMdgV826jo%3D
Vulnerable Package
HIGH CVE-2025-52999 Maven-com.fasterxml.jackson.core:jackson-core-2.10.3
detailsRecommended version: 2.15.0
Description: The jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In versions pr...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: u57rzVfJ0%2Fbpe73N%2BA1fGeIJ2JimQphSSoLlbWREeoc%3D
Vulnerable Package
MEDIUM CVE-2025-49128 Maven-com.fasterxml.jackson.core:jackson-core-2.12.0
detailsRecommended version: 2.15.0
Description: Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In com.fasterxml.j...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: l73wkCSLmwMbg9920K9gYud8SGfIlH3PoNKI0s8VGTA%3D
Vulnerable Package
MEDIUM CVE-2025-49128 Maven-com.fasterxml.jackson.core:jackson-core-2.10.3
detailsRecommended version: 2.15.0
Description: Jackson-core contains core low-level incremental ("streaming") parser and generator abstractions used by Jackson Data Processor. In com.fasterxml.j...
Attack Vector: LOCAL
Attack Complexity: LOW

ID: Z2ywWOsjwlqQ3%2FyqC4UIAxRJI1ZPR5VW4QNQK22ZVa4%3D
Vulnerable Package
MEDIUM CVE-2025-53864 Maven-com.google.code.gson:gson-2.8.5
detailsRecommended version: 2.12.0
Description: Connect2id Nimbus JOSE + JWT allows a remote attacker to cause a Denial-of-Service (DoS) via a deeply nested JSON object supplied in a JWT claim se...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Ac7JsuEB%2FQJq2Gb7Q0iEl12520orMzUegMsRfE7ixR4%3D
Vulnerable Package
LOW Unpinned Actions Full Length Commit SHA /stale_issue.yml: 13
detailsPinning an action to a full length commit SHA is currently the only way to use an action as an immutable release. Pinning to a particular SHA help...
ID: t7QLW7aAeEY99HHKqLRYUX2tA9o%3D
Fixed Issues (21)

Great job! The following issues were fixed in this Pull Request

Severity Issue Source File / Package
HIGH CVE-2018-1000180 Gradle-org.bouncycastle:bcprov-jdk15on-1.56
HIGH CVE-2018-1000613 Gradle-org.bouncycastle:bcprov-jdk15on-1.56
HIGH CVE-2019-17359 Gradle-org.bouncycastle:bcprov-jdk15on-1.56
HIGH CVE-2021-35515 Gradle-org.apache.commons:commons-compress-1.12
HIGH CVE-2021-35516 Gradle-org.apache.commons:commons-compress-1.12
HIGH CVE-2021-35517 Gradle-org.apache.commons:commons-compress-1.12
HIGH CVE-2021-36090 Gradle-org.apache.commons:commons-compress-1.12
HIGH CVE-2022-3171 Gradle-com.google.protobuf:protobuf-java-3.10.0
HIGH CVE-2022-3509 Gradle-com.google.protobuf:protobuf-java-3.10.0
HIGH Cxa9261daf-3755 Gradle-org.bouncycastle:bcprov-jdk15on-1.56
HIGH Cxdfe95b9f-ea87 Gradle-org.jetbrains.kotlin:kotlin-compiler-embeddable-1.3.72
MEDIUM CVE-2018-11771 Gradle-org.apache.commons:commons-compress-1.12
MEDIUM CVE-2018-1324 Gradle-org.apache.commons:commons-compress-1.12
MEDIUM CVE-2020-13956 Gradle-org.apache.httpcomponents:httpclient-4.5.6
MEDIUM CVE-2020-15522 Gradle-org.bouncycastle:bcprov-jdk15on-1.56
MEDIUM CVE-2020-17521 Gradle-org.codehaus.groovy:groovy-all-2.4.15
MEDIUM CVE-2020-26939 Gradle-org.bouncycastle:bcprov-jdk15on-1.56
MEDIUM CVE-2020-29582 Gradle-org.jetbrains.kotlin:kotlin-compiler-embeddable-1.3.72
MEDIUM CVE-2021-22569 Gradle-com.google.protobuf:protobuf-java-3.10.0
LOW CVE-2020-8908 Gradle-com.google.guava:guava-28.1-jre
LOW Cxeb68d52e-5509 Gradle-commons-codec:commons-codec-1.10

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant