Skip to content

NO-SNOW bump to netty 4.1.132.Final (CVE-2026-33870 & CVE-2026-33871)#2561

Merged
sfc-gh-dszmolka merged 3 commits intomasterfrom
NO-SNOW-bump-netty
Mar 31, 2026
Merged

NO-SNOW bump to netty 4.1.132.Final (CVE-2026-33870 & CVE-2026-33871)#2561
sfc-gh-dszmolka merged 3 commits intomasterfrom
NO-SNOW-bump-netty

Conversation

@sfc-gh-dszmolka
Copy link
Copy Markdown
Contributor

@sfc-gh-dszmolka sfc-gh-dszmolka commented Mar 25, 2026

Description

Dependency bump:

  • netty dependency bump 4.1.130.Final -> fresh 4.1.132.Final to address 2 High CVE mentioned in the title
  • Also grpc-java to 1.80.0 but they're still on netty 4.1.130.Final so will need to bump again when they have the fix for the same.
    • this now needs a newer animal-sniffer-annotations 1.24 -> 1.26

@sfc-gh-dszmolka sfc-gh-dszmolka marked this pull request as ready for review March 25, 2026 16:18
@sfc-gh-dszmolka sfc-gh-dszmolka requested a review from a team as a code owner March 25, 2026 16:18
@sfc-gh-dszmolka sfc-gh-dszmolka merged commit 4eea791 into master Mar 31, 2026
115 of 122 checks passed
@sfc-gh-dszmolka sfc-gh-dszmolka deleted the NO-SNOW-bump-netty branch March 31, 2026 10:58
@github-actions github-actions bot locked and limited conversation to collaborators Mar 31, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants