-
Notifications
You must be signed in to change notification settings - Fork 894
Please update netty to v4.1.42 in netty-nio-client #1471
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
Hi! When can we expect to see this released? |
@testphreak have open #1480 to make this change. Should be released either tomorrow or Wednesday. |
@spfink thank you for the update. If you or your team would like to get ahead on security vulnerabilities in your dependencies and would like to integrate security scans into your development lifecycle, you can use Sonatype's AppScan. That's how we came across this security issue. Maybe there are other tools out there that do something similar. |
Nice! Thanks for the update. |
…c785fa3a6 Pull request: release <- staging/53291cf4-d02e-433a-813c-c29c785fa3a6
netty-nio-client
dependency insoftware.amazon.awssdk:kms:jar
uses netty v4.1.41 that has a security as described here. A fix for the issue was released 19 days ago with v4.1.42 as described here. Please update netty insidenetty-nio-client
to the new version.Steps to Reproduce (for bugs)
mvn dependency:tree
Context
This issue affects us because security scans have been flagging the issue lately as a critical vulnerability. As a result we would like to see the netty version updated as soon as possible.
Your Environment
The text was updated successfully, but these errors were encountered: