Skip to content

Conversation

@0marperez
Copy link
Contributor

@0marperez 0marperez commented Jun 10, 2025

Issue #, if available:
Fixes https://github.com/awslabs/aws-crt-kotlin/security/dependabot/28

Description of changes:
We're already using the latest version of Netty. Which relies on vulnerable version of beanutils. We need to force the resolution strategy to use a non-vulnerable version.

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@0marperez 0marperez added the no-changelog Indicates that a changelog entry isn't required for a pull request. Use sparingly. label Jun 10, 2025
@sonarqubecloud
Copy link

@github-actions

This comment has been minimized.

1 similar comment
@github-actions
Copy link

Affected Artifacts

Changed in size
Artifact Pull Request (bytes) Latest Release (bytes) Delta (bytes) Delta (percentage)
aws-crt-kotlin-jvm.jar 215,750 215,568 182 0.08%

@0marperez 0marperez marked this pull request as ready for review June 10, 2025 20:14
@0marperez 0marperez requested a review from a team as a code owner June 10, 2025 20:14
@0marperez
Copy link
Contributor Author

Closing due to https://github.com/awslabs/aws-crt-kotlin/security/dependabot/28 being dismissed

@0marperez 0marperez closed this Jun 11, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-changelog Indicates that a changelog entry isn't required for a pull request. Use sparingly.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant