Ashi Bhardwaj
07/31/2025, 2:01 PMprocessing/src/main/java/org/apache/druid/crypto/CryptoService.java.
I have only made changes to pac4j extension in this PR and didn't change the algorithm and fixing this unrelated check will require significant change and testing in the other module.
How can I get my PR merged in such a scenario?
CC: @Lucas Capistrant (since you've been reviewing the PR)Gian Merlino
08/02/2025, 9:08 AMAshi Bhardwaj
08/02/2025, 9:09 AMAshi Bhardwaj
08/21/2025, 1:42 PMAshi Bhardwaj
08/21/2025, 1:55 PMAshi Bhardwaj
08/23/2025, 4:42 PMpotentially-weak-cryptographic-algorithm codeQL check for my PR and now all github checks are passing. I will add it back as soon as my PR is merged as mentioned in the PR description as well.
Can I please get this reviewed and merged? We have been running this pac4j upgrade in our production clusters at Confluent without any issues for a while now and it significantly improves the security posture of Druid by fixing severe vulnerabilities.
cc: @Lucas Capistrant @Gian MerlinoAshi Bhardwaj
09/01/2025, 9:05 AM