Skip to content

io.netty:netty-handler:4.1.116.Final is flagged by dependabot #1078

Closed
@ansf

Description

@ansf

firebase-admin-java has a dependency to io.netty:netty-handler:4.1.116.Final.
This version of netty-handler is flagged by dependabot, see GHSA-4g8c-wm8x-jfhw

For the fixed version 4.1.118 there is already a pull request: #1074

This might not be a critical issue to firebase-admin-java, but it would be nice if you could publish a release after merging the PR.

Activity

google-oss-bot

google-oss-bot commented on Feb 20, 2025

@google-oss-bot

I couldn't figure out how to label this issue, so I've labeled it for a human to triage. Hang tight.

jonathanedey

jonathanedey commented on May 29, 2025

@jonathanedey
Contributor

Thanks for your patience, this is now resolved in v9.5.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

      Development

      No branches or pull requests

        Participants

        @ansf@google-oss-bot@jonathanedey

        Issue actions

          io.netty:netty-handler:4.1.116.Final is flagged by dependabot · Issue #1078 · firebase/firebase-admin-java