fix(security): align Netty runtime on 4.1.136.Final - #269
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
@opencode-agent Complete this bounded clean PR on exact current head Required work:
Refuse an empty component set, mixed Netty line, hand-edited generated graph, or stale-head result. Keep the PR draft and report the exact new head for fresh review. |
|
@coderabbitai review @cwl-noema-review Independently inspect exact current head |
Rate Limit Exceeded
|
|
@opencode-agent Continue from exact current head The repository evidence contract is now test-first and red on the exact head. CI run Generate the CycloneDX aggregate SBOM from this exact branch with the canonical Maven command, regenerate third-party attribution only through |
|
Exact head advanced only by the focused changelog entry to |
|
Superseded by draft #270. #269's bounded Netty property, real-POM regression, and ADR are preserved in #270, while #270 also contains the complete generated CycloneDX SBOM, deterministic attribution, full Netty component/purl/bom-ref/dependency-edge drift contract, corrected Maven property documentation, hashes, and privacy parent required for one coherent protected merge. #269's current CI failure reflects the intentionally incomplete historical SBOM and is not ignored; the valid fix and regenerated evidence are carried by #270. No #269 check or review is reused as final #270 evidence. |
|
Closing as superseded by integrated replacement #270. #270 exact head |
Security objective
Move the complete Spring Boot-managed Netty 4.1 module family from
4.1.135.Finalto the reviewed4.1.136.Finalsecurity line after exact-head Strix run30997430437reported newly published HIGH findings against the prior line.This is deliberately separate from privacy PR #267. It contains only the Netty runtime version contract, its regression test, and the architecture decision. It must not absorb audit-pseudonymization, administrative authorization, or unrelated workflow changes.
Changes
netty.versionproperty rather than individual mixed-module pins.4.1.136.Final.Test-first evidence
The dependency-policy test names the fixed line and fails if the root POM omits or changes the coordinated override. The production change is limited to dependency resolution; no Clearfolio API or application logic changes.
Required buyer-evidence work
The dated CycloneDX SBOM and generated third-party attribution still describe the prior Netty line. Before this PR is ready:
4.1.136.Finaland no current evidence contains4.1.135.Final;CHANGELOG.mdwithout duplicating its existing cleanup work.Hand-editing package URLs, hashes, dependency edges, or generated evidence is prohibited.
Merge gate
Keep this PR draft until the generated evidence and changelog are complete and the exact current head has successful CI, dependency tree, Security Scan, SAST, fuzzing, Strix, CodeRabbit/OpenCode/Noema review, zero unresolved threads, and an independent approving review whose repository permission GitHub counts. Do not bypass protections, use self-mutating repair workflows, weaken tests, or count stale-head evidence.