Skip to content

Bump netty version to 4.1.77.Final#3273

Merged
nicoloboschi merged 1 commit intoapache:masterfrom
hezhangjian:netty-4-1-77
May 19, 2022
Merged

Bump netty version to 4.1.77.Final#3273
nicoloboschi merged 1 commit intoapache:masterfrom
hezhangjian:netty-4-1-77

Conversation

@hezhangjian
Copy link
Copy Markdown
Member

Motivation

original PR #3091
Changelog: https://netty.io/news/2022/05/06/2-1-77-Final.html

Modifications

  • Upgrade Netty from 4.1.75.Final to 4.1.77.Final
  • Netty 4.1.77.Final depends on netty-tc-native 2.0.52, also updates

@hezhangjian
Copy link
Copy Markdown
Member Author

rerun failure checks

@hezhangjian
Copy link
Copy Markdown
Member Author

@nicoloboschi @dlg99 @eolivelli @merlimat
Although the OWASP Dependency check is failed, but can we merge it? Netty is not related to this fail(google-http-client-gson-1.41.0.jar: CVE-2022-25647(7.5))

I think that we need another grpc PR to solve it.

@CalvinKirs
Copy link
Copy Markdown
Member

@nicoloboschi @dlg99 @eolivelli @merlimat Although the OWASP Dependency check is failed, but can we merge it? Netty is not related to this fail(google-http-client-gson-1.41.0.jar: CVE-2022-25647(7.5))

I think that we need another grpc PR to solve it.

on dependency upgrades, it's best to solve the corresponding CI failure first. You can submit a new PR to solve this problem alone. When this problem is solved, then back to this PR, otherwise, we cannot fast ensure whether this PR will introduce new problems.

@hezhangjian
Copy link
Copy Markdown
Member Author

@CalvinKirs Now we check CVE when pom file changes. If netty and grpc both have CVE now, we need to update netty and grpc in one pr. I think it's quite unreasonable.

@CalvinKirs
Copy link
Copy Markdown
Member

@CalvinKirs Now we check CVE when pom file changes. If netty and grpc both have CVE now, we need to update netty and grpc in one pr. I think it's quite unreasonable.

I mean, don't rush to merge this PR, if you are sure that this is a problem caused by the GRPC version, you can submit a new PR to solve it(Grpc), and then come back to this PR(Netty).

Copy link
Copy Markdown
Contributor

@nicoloboschi nicoloboschi left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

we can merge it, the related owasp failure is a false positive and not related to this pull

@nicoloboschi nicoloboschi merged commit 4bbdaf8 into apache:master May 19, 2022
@nicoloboschi nicoloboschi added this to the 4.16.0 milestone May 19, 2022
@hezhangjian hezhangjian deleted the netty-4-1-77 branch May 19, 2022 15:03
Ghatage pushed a commit to sijie/bookkeeper that referenced this pull request Jul 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants