Skip to content

Bump netty version to 4.1.77.Final - #3273

Merged
nicoloboschi merged 1 commit into
apache:masterfrom
hezhangjian:netty-4-1-77
May 19, 2022
Merged

Bump netty version to 4.1.77.Final#3273
nicoloboschi merged 1 commit into
apache:masterfrom
hezhangjian:netty-4-1-77

Conversation

@hezhangjian

Copy link
Copy Markdown
Member

Motivation

original PR #3091
Changelog: https://netty.io/news/2022/05/06/2-1-77-Final.html

Modifications

  • Upgrade Netty from 4.1.75.Final to 4.1.77.Final
  • Netty 4.1.77.Final depends on netty-tc-native 2.0.52, also updates

@hezhangjian

Copy link
Copy Markdown
Member Author

rerun failure checks

@hezhangjian

Copy link
Copy Markdown
Member Author

@nicoloboschi @dlg99 @eolivelli @merlimat
Although the OWASP Dependency check is failed, but can we merge it? Netty is not related to this fail(google-http-client-gson-1.41.0.jar: CVE-2022-25647(7.5))

I think that we need another grpc PR to solve it.

@CalvinKirs

Copy link
Copy Markdown
Member

@nicoloboschi @dlg99 @eolivelli @merlimat Although the OWASP Dependency check is failed, but can we merge it? Netty is not related to this fail(google-http-client-gson-1.41.0.jar: CVE-2022-25647(7.5))

I think that we need another grpc PR to solve it.

on dependency upgrades, it's best to solve the corresponding CI failure first. You can submit a new PR to solve this problem alone. When this problem is solved, then back to this PR, otherwise, we cannot fast ensure whether this PR will introduce new problems.

@hezhangjian

Copy link
Copy Markdown
Member Author

@CalvinKirs Now we check CVE when pom file changes. If netty and grpc both have CVE now, we need to update netty and grpc in one pr. I think it's quite unreasonable.

@CalvinKirs

Copy link
Copy Markdown
Member

@CalvinKirs Now we check CVE when pom file changes. If netty and grpc both have CVE now, we need to update netty and grpc in one pr. I think it's quite unreasonable.

I mean, don't rush to merge this PR, if you are sure that this is a problem caused by the GRPC version, you can submit a new PR to solve it(Grpc), and then come back to this PR(Netty).

@nicoloboschi nicoloboschi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we can merge it, the related owasp failure is a false positive and not related to this pull

@nicoloboschi
nicoloboschi merged commit 4bbdaf8 into apache:master May 19, 2022
@nicoloboschi nicoloboschi added this to the 4.16.0 milestone May 19, 2022
@hezhangjian
hezhangjian deleted the netty-4-1-77 branch May 19, 2022 15:03
Ghatage pushed a commit to sijie/bookkeeper that referenced this pull request Jul 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants