Skip to content

Conversation

@zymap
Copy link
Member

@zymap zymap commented Jul 1, 2022


Motivation

We upgrade the Netty Reactive Stream in the PR #15990,
but the asynchttpclient still uses it. We should use
our project dependency to address the CVE.

  • doc-not-needed

---

*Motivation*

We upgrade the Netty Reactive Stream in the PR apache#15990,
but the asynchttpclient still uses it. We should use
our project dependency to address the CVE.
@zymap zymap added area/dependency Pull requests that update a dependency file release/2.10.2 release/2.9.4 labels Jul 1, 2022
@zymap zymap added this to the 2.11.0 milestone Jul 1, 2022
@zymap zymap self-assigned this Jul 1, 2022
@github-actions
Copy link

github-actions bot commented Jul 1, 2022

@zymap Please provide a correct documentation label for your PR.
Instructions see Pulsar Documentation Label Guide.

@zymap zymap added doc-not-needed Your PR changes do not impact docs and removed doc-label-missing labels Jul 1, 2022
@zymap zymap merged commit f9e89ed into apache:master Jul 5, 2022
codelipenghui pushed a commit that referenced this pull request Jul 10, 2022
* Exclude the Netty Reactive Stream from asynchttpclient
---

*Motivation*

We upgrade the Netty Reactive Stream in the PR #15990,
but the asynchttpclient still uses it. We should use
our project dependency to address the CVE.

* Add the related dependency to the sub module

(cherry picked from commit f9e89ed)
nicoloboschi pushed a commit to datastax/pulsar that referenced this pull request Jul 11, 2022
* Exclude the Netty Reactive Stream from asynchttpclient
---

*Motivation*

We upgrade the Netty Reactive Stream in the PR apache#15990,
but the asynchttpclient still uses it. We should use
our project dependency to address the CVE.

* Add the related dependency to the sub module

(cherry picked from commit f9e89ed)
(cherry picked from commit b5479ee)
wuxuanqicn pushed a commit to wuxuanqicn/pulsar that referenced this pull request Jul 14, 2022
* Exclude the Netty Reactive Stream from asynchttpclient
---

*Motivation*

We upgrade the Netty Reactive Stream in the PR apache#15990,
but the asynchttpclient still uses it. We should use
our project dependency to address the CVE.

* Add the related dependency to the sub module
@mattisonchao mattisonchao added the cherry-picked/branch-2.9 Archived: 2.9 is end of life label Aug 10, 2022
mattisonchao pushed a commit that referenced this pull request Aug 10, 2022
* Exclude the Netty Reactive Stream from asynchttpclient
---

*Motivation*

We upgrade the Netty Reactive Stream in the PR #15990,
but the asynchttpclient still uses it. We should use
our project dependency to address the CVE.

* Add the related dependency to the sub module

(cherry picked from commit f9e89ed)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/dependency Pull requests that update a dependency file cherry-picked/branch-2.9 Archived: 2.9 is end of life cherry-picked/branch-2.10 doc-not-needed Your PR changes do not impact docs release/2.9.4 release/2.10.2

Projects

None yet

Development

Successfully merging this pull request may close these issues.

9 participants