Skip to content

Conversation

@Bouncheck
Copy link

This rids us of CVE-2024-47535.

@Bouncheck Bouncheck force-pushed the scylla-4.x-bump-netty-115 branch from 398afaf to fe90f4f Compare November 20, 2024 12:59
@mykaul
Copy link

mykaul commented Nov 20, 2024

This rids us of CVE-2024-47535.

I did not think it is important, as the above CVE is Windows-specific. But it's good to update anyway.

@Bouncheck
Copy link
Author

Bouncheck commented Nov 20, 2024

I agree it's not important, but companies run security scanners and expect (almost) every CVE to be gone. Kafka connectors are affected so we need to update that dependency or we risk not being listed on confluent hub for example.

@mykaul
Copy link

mykaul commented Nov 20, 2024

I agree it's not important, but companies run security scanners and expect (almost) every CVE to be gone. Kafka connectors are affected so we need to update that dependency or we risk not being listed on confluent hub for example.

Yes, that's why I'm in favor of it, just not high prio ;-)

@dkropachev dkropachev merged commit a010b28 into scylladb:scylla-4.x Nov 20, 2024
9 of 10 checks passed
@dkropachev
Copy link

@Bouncheck , do we want to do the same for 3.x ?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants