Security improvements

This section lists changes made to improve Sinch Contact Pro security.

Java-based open source libraries have been updated:

  • amazon.awssdk:bom 2.26.30 → 2.28.19

  • amazon.awssdk:xray 2.25.46 → 2.30.23

  • commons-codec 1.17.0 →1.18.0

  • commons-compress 1.26.1→1.27.1

  • commons-lang3 3.14.0 → 3.17.0

  • jackson-annotations 2.15.2 → 2.18.0

  • jackson-core 2.17.1 → 2.18.3

  • jackson-databind 2.17.2 → 2.18.0

  • java-jwt 4.4.0 → 4.5.0

  • jaxb-impl 2.3.8 → 2.3.9

  • jaxws-rt 2.3.6 → 2.3.7

  • jersey-container-servlet 2.44 → 2.45

  • jersey-media-jaxb 2.43→ 2.44

  • jersey-media-json-jackson 2.45 → 2.46

  • jna 5.13.0 → 5.17.0

  • jna-platform 5.14.0 → 5.15.0

  • json 20231013 → 20240303

  • junit-jupiter-api 5.10.2 → 5.12.1

  • junit-vintage-engine 5.10.2 → 5.11.2

  • log4j-api 2.20.0 → 2.24.3

  • mssql-jdbc 12.4.1.jre11 → 12.10.0.jre11

  • mssql-jdbc_auth 12.6.1.jre11 → 12.8.1.x86

  • poi-ooxml 5.2.5 → 5.4.0

  • tomcat 9.0.93 → 9.0.102

  • tomcat-catalina 9.0.88 → 9.0.93

  • woodstox-core 6.6.2 → 6.7.0

  • xmlsec 3.0.2 → 4.0.3

  • xray 2.21.41 → 2.31.15

.NET libraries have been updated to the latest versions:

  • Azure.Core 1.42.0 → 1.44.1

  • Azure.Identity 1.13.1 → 1.13.2

  • Microsoft.Graph 5.56.0 → 5.68

  • Microsoft.Graph.Core 3.1.12 → 3.1.14

  • Microsoft.Identity.Client 4.61.1 → 4.63.0

  • Microsoft.IdentityModel.Abstractions 7.6.0 → 8.0.1

  • Microsoft.IdentityModel.JsonWebTokens 7.6.0 → 8.0.1

  • Microsoft.IdentityModel.Logging 7.6.0 → 8.0.1

  • Microsoft.IdentityModel.Protocols 7.6.0 → 8.0.1

  • Microsoft.IdentityModel.Protocols.OpenIdConnect 7.6.0 → 8.0.1

  • Microsoft.IdentityModel.Tokens 7.6.0 → 8.0.1

  • Microsoft.Kiota.Abstractions 1.9.3 → 1.11.0

  • Microsoft.Kiota.Authentication.Azure 1.1.7 → 1.11.0

  • Microsoft.Kiota.Http.HttpClientLibrary 1.4.3 → 1.11.0

  • Microsoft.Kiota.Serialization.Form 1.2.4 → 1.11.0

  • Microsoft.Kiota.Serialization.Json 1.3.3 → 1.11.0

  • Microsoft.Kiota.Serialization.Multipart 1.1.5 → 1.11.0

  • Microsoft.Kiota.Serialization.Text 1.2.2 → 1.11.0

  • Std.UriTemplate 0.0.57 → 1.0.5

  • System.IdentityModel.Tokens.Jwt 7.6.0 → 8.0.1

  • System.Net.Http.WinHttpHandler 8.0.0 → 8.0.1

  • System.Text.Json 8.0.3 → 8.0.4

Secret data in RI logs

Secret data such as authentication details are now hidden by default in RI logs. It is possible to log all data as before by using LogDetails registry setting's ShowSecrets option but this is not recommended. ID: SCC-12643